CY0-001 Exam Questions
97 real CY0-001 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Threat Management
An organization is concerned with the exposure of sensitive data. Which of the following is the most relevant security concern?
model inversionsensitive data exposureAI model attacksdata privacy - Question #2Security Architecture and Tool Sets
Faculty members at a university are concerned about potential inherent bias and inconsistency in one department's AI plagiarism detection service. Which of the following principles...
AI ethicsbias mitigationconsistencyAI governance - Question #3Security Architecture and Tool Sets
A security administrator must provide access controls for AI systems to list tables. Which of the following should the administrator implement?
data access controlAI systemsaccess managementleast privilege - Question #4Security Architecture and Tool Sets
A machine learning (ML) engineer is working with a security engineer to identify the best practices for securing a system with various AI models. Which of the following actions sho...
MDLCsecure model developmentAI security lifecyclebest practices - Question #5Cyber Incident Response
Which of the following is an example of how a security analyst uses generative AI in the triage process?
generative AItriagesecurity operationsAI-assisted analysis - Question #6Threat Management
A company develops an AI model to diagnose patients. Hospitals access the model through an integrated application programming interface (API). The security team performs a denial-o...
DoS preventionrate limitingAPI securityAI model protection - Question #7Vulnerability Management
A security team is using an AI-based tool to try to bypass organizational boundaries. The team uses AI to look at the current state and suggest different attack vectors based on th...
automated penetration testingAI-driven attacksattack vectorsred teaming - Question #8Vulnerability Management
Which of the following attacks would be the best to automate with AI during dynamic application software testing (DAST)?
DASTpayload creationAI automationapplication security testing - Question #9Threat Management
A disgruntled employee changed the company policies that a chatbot references in order to create confusion and disrupt the business. Which of the following AI-generated vulnerabili...
data poisoninginsider threatchatbot securityRAG poisoning - Question #10Security Architecture and Tool Sets
A security consultant must summarize the impact of posture management on a machine learning (ML) use case. Which of the following is the most appropriate reference for this purpose...
NIST AI RMFposture managementAI governanceML risk management - Question #11Security Architecture and Tool Sets
A cybersecurity analyst must use pattern recognition on a data set containing unstructured data. Which of the following models is the best for this task?
CNNpattern recognitionunstructured dataML model selection - Question #12Security Architecture and Tool Sets
An employee wants a consulting company to procure a data set that contains age, ethnicity, and diabetes status. During development, the employer wants to ensure the integrity of th...
data integritychecksumsML dataset securitydata validation - Question #13Threat Management
Which of the following strengthens the performance of a large language model (LLM) for malicious reconnaissance?
RAGLLM enhancementoffensive AImalicious reconnaissance - Question #14Vulnerability Management
A social media company with more than a million lines of code wants to reduce the mean time to fix bugs and issues. Which of the following is the most balanced AI strategy to autom...
AI automationvulnerability management workflowhuman oversightDevSecOps - Question #15Security Architecture and Tool Sets
Which of the following would most likely be used to prove that an image is AI generated?
watermarkingAI-generated contentcontent authenticitydigital forensics - Question #16Threat Management
Which of the following controls is the best way to mitigate a denial-of-service (DoS) attack?
DoS mitigationrate limitingavailabilitynetwork security - Question #17Security Architecture and Tool Sets
A group of security engineers is developing a security incident and event management (SIEM) system that will: - Be able to ingest data from multiple structured and unstructured sou...
data cleansingSIEMLLM integrationdata ingestion - Question #18Security Architecture and Tool Sets
A company uses human review for software development validation and wants to add another validation layer. Which of the following should a security administrator use to accomplish...
AI-assisted validationsoftware developmentcode reviewapproval workflow - Question #19Security Architecture and Tool Sets
A team of data scientists is ready to release a model for enterprise use. The team wants to protect the model from unintentional changes or tampering. Which of the following is the...
model integrityIAMAPI securityaccess control - Question #20Threat Management
An architect is creating a threat model for an agentic system. Which of the following should the architect do first?
threat modelingagentic AItrust boundariessecurity architecture - Question #21Vulnerability Management
A security analyst is aware of an active penetration test in the environment. The analyst examines security information and event management (SIEM) log data and notices the followi...
sensitive information disclosureAI securitydata maskingSIEM analysis - Question #22Security Architecture and Tool Sets
A recently deployed AI system becomes persistently unavailable. A restart temporarily fixes the issue, but the issue happens again. Upon examination of application programming inte...
session managementAPI securityavailabilityAI system security - Question #23Vulnerability Management
A security analyst receives an alert about an AI system and is investigating the following output: Which of the following is the most appropriate control the analyst should recomme...
input validationAI securityprompt injectionmodel output control - Question #24Security Architecture and Tool Sets
An organization develops a chatbot with the following requirements: - Does not provide harmful or explicit responses - Must use clean and professional language - Ensures that respo...
AI guardrailspre-deployment testingchatbot securitymodel validation - Question #25Security Architecture and Tool Sets
An AI security administrator notices that the information referenced by the model is incorrectly formatted and missing values. Which of the following job roles would most likely be...
data engineeringAI rolesdata qualitymodel data - Question #26Security Architecture and Tool Sets
Which of the following describe the practice of providing examples in a prompt? (Choose two.)
prompt engineeringone-shot promptingmulti-shot promptingfew-shot learning - Question #27Security Architecture and Tool Sets
A user interface engineer adds new graphics to the latest release of an AI-integrated application. During the update, the engineer accidentally causes the model to retain on unveri...
model development lifecycleAI governanceunverified training datamodel management - Question #28Threat Management
A short AI-generated video shows a celebrity's likeness talking about a fake public security event. Which of the following was used to create this video?
deepfakeconvolutional neural networksynthetic mediaAI-generated content - Question #29Threat Management
An AI security team must assess the probability of an attack on its new system and the impact associated with such an attack. Which of the following threat-modeling resources best...
threat modelingMITRE ATLASML securityAI threat landscape - Question #32Security Architecture and Tool Sets
SIMULATION Instructions Part1 Use drop-down menu to select the most appropriate protocol or cipher for each system component. Part2 Use the drop-down menu to select the most approp...
data encryptioncryptographic protocolsdata securitypenetration test remediation - Question #33Cyber Incident Response
A SOC analyst notices a sudden spike in outbound traffic from a server. The traffic is being sent continuously to an unknown external IP address. Which of the following BEST descri...
data exfiltrationnetwork traffic analysisoutbound trafficSOC monitoring - Question #34Vulnerability Management
A company discovers that attackers exploited an unpatched vulnerability in a web server. Which control BEST prevents this?
patch managementvulnerability remediationweb server securityunpatched vulnerabilities - Question #35Threat Management
Which of the following are considered threat intelligence sources? (Choose two.)
threat intelligenceISACOSINTintelligence sources - Question #36Threat Management
A malware sample alters itself slightly each time it runs to evade signature detection. What technique is this?
polymorphic malwareevasion techniquessignature detection bypassmalware analysis - Question #37Threat Management
An analyst finds failed login attempts across multiple systems using different usernames but from the same IP. Which attack is MOST likely?
password sprayingcredential attacksauthentication attacksbrute force variants - Question #38Security Architecture and Tool Sets
Which of the following job roles in an organizational governance structure develops a model from business use cases?
AI rolesdata scientistorganizational governanceML model development - Question #39Security Architecture and Tool Sets
An administrator, who works for a financial institution, is required to implement data security controls for data at rest within AI systems that involve data disclosure. Which of t...
data at rest encryptionfinancial data securityAI data protectiondata security controls - Question #40Security Architecture and Tool Sets
A security engineer needs to monitor an AI-based system for runtime operations. The engineer is mostly concerned about the visibility of internal activity. Which of the following i...
AI monitoringruntime observabilitydebug tracinginternal activity visibility - Question #41Security Architecture and Tool Sets
Which of the following should an auditor reference when reviewing a company's human resources AI systems for legal non-compliance?
EU AI ActAI complianceAI governanceHR AI systems - Question #42Security Architecture and Tool Sets
An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers: - Can ask question and receive answers about flight details. -...
LLM securityprompt guardrailstoken quotasAI input validation - Question #43Threat Management
A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of machine learning (ML) system to help with triage. Which of...
SOC operationsML-based triagealert classificationlog analysis - Question #44Security Architecture and Tool Sets
An organization recently created a custom model that integrates with a language model (LLM). The developer notices that the application programming interface (API) costs have incre...
LLM API coststoken limitsAI cost optimizationprompt engineering - Question #45Threat Management
A security administrator needs to improve an AI model. During an initial investigation, the administrator notices that two successive login features are recorded every day, and the...
pattern recognitionAI model improvementlogin anomaly detectionbehavioral analysis - Question #46Threat Management
Which of the following is the most concerning risk for a company that allows corporate end users to use public-facing large language models (LLMs)?
LLM risksdata leakageregulatory compliancepublic AI usage - Question #47Security Architecture and Tool Sets
Which of the following requires developers to harden infrastructure to protect AI systems?
infrastructure hardeningconfiguration standardsAI security governancedevelopment guidelines - Question #48Security Architecture and Tool Sets
Which of the following is the best example of an AI model that is trained to identify multiple points from input using a neural network to provide output for authentication?
facial recognitionneural networksbiometric authenticationAI authentication - Question #49Vulnerability Management
A vulnerability scan produces many false positives. What does this indicate?
false positivesscan sensitivityscan specificityvulnerability scanning - Question #50Threat Management
Which are indicators of lateral movement? (Choose two.)
lateral movementPass-the-HashSMB authenticationthreat indicators - Question #51Threat Management
A company wants to reduce IDS false positives. What tuning should occur FIRST?
IDS tuningfalse positive reductionbehavioral baselinesignature tuning - Question #52Threat Management
A phishing attachment appears harmless during static analysis but behaves maliciously when executed. Which technique would detect this?
sandbox analysisdynamic analysisevasion techniquesmalware detection