CompTIA CY0-001 Exam Prep
CompTIA SecAI+ (Page 5 )

Updated On: 1-Oct-2026

An attacker successfully completes a denial-of-service (DoS) attack through the context window of an AI system. Thousands of characters are obfuscated and hidden behind an emoji.
Which of the following techniques best mitigates this type of attack?

  1. Fraud detection
  2. Large language model (LLM)-as-a-judge
  3. Pattern recognition
  4. Prompt filter

Answer(s): D

Explanation:

A DoS attack through the context window relies on overwhelming the model with excessive or obfuscated input. Prompt filtering prevents such malicious or oversized inputs from being processed, ensuring that the model only receives safe, properly structured data within acceptable limits.



An AI architect reviews AI utilization and wants to improve the user experience.
Which of the following should the architect review within the logs?

  1. Rate monitoring
  2. Model accuracy
  3. Access controls
  4. Data storage

Answer(s): B

Explanation:

To improve user experience, the architect should review model accuracy in the logs. High accuracy ensures users receive relevant, reliable responses, directly impacting satisfaction and effectiveness of the AI system.



A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the query parameters and includes an example resume that matches a successful candidate.
Which if the following best describes this query?

  1. Distillation
  2. Prompt template
  3. One-shot prompting
  4. System role

Answer(s): C

Explanation:

One-shot prompting provides the model with a single example (in this case, a successful resume) to guide how it should process future inputs. This technique helps the AI better align its output with the desired evaluation criteria.



A line of business wants to onboard an application that uses a custom AI model for employee assessments. The Chief Information Officer (CIO) agrees to allow the engagement to proceed but first wants a threat model.
Which of the following is the most appropriate to use for an AI threat model?

  1. Responsible AI
  2. Adversarial Threat Landscape for AI Systems (ATLAS)
  3. Organization for Economic Co-operation and Development (OECD)
  4. International Organization for Standardization (ISO)

Answer(s): B

Explanation:

ATLAS is specifically designed for creating AI threat models. It catalogs adversarial techniques, tactics, and use cases that target AI systems, making it the most appropriate framework for assessing risks to a custom AI model in employee assessments.



A security analyst finds that the AI system is under a denial-of-wallet attack.
Which of the following should the analyst enforce to protect the company? (Choose two.)

  1. Endpoint access controls
  2. Content delivery network (CDN)
  3. Model fine-tuning
  4. Modality controls
  5. Application programming interface (API) rate controls
  6. Output token controls

Answer(s): E,F

Explanation:

API rate controls limit the number of requests within a set timeframe, preventing attackers from overloading the system and driving up costs.
Output token controls restrict the length of responses, reducing unnecessary token usage that attackers might exploit in a denial-of-wallet attack.



Viewing page 5 of 31
Viewing questions 21 - 25 out of 149 questions


Post your Comments and Discuss CompTIA CY0-001 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!