CY0-001 Exam Questions
97 real CY0-001 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #53Security Architecture and Tool Sets
Which of the following technologies is used in deepfake?
deepfakeGANAI-generated contentadversarial ML - Question #54Security Architecture and Tool Sets
During the selection of a machine learning (ML)-based threat classification model, a cybersecurity administrator verifies that label distribution is highly unbalanced. Which of the...
ML model trainingdata augmentationclass imbalancethreat classification - Question #55Security Architecture and Tool Sets
A healthcare organization plans to deploy a chatbot for appointment scheduling and patient records. Which of the following is the first step a security administrator should take?
risk assessmentAI deploymenthealthcare data securitychatbot security - Question #56Security Architecture and Tool Sets
Which of the following helps in managing potential security issues related to model training?
NIST AI RMFAI governancemodel training securityrisk management frameworks - Question #57Security Architecture and Tool Sets
Which of the following improves the observability and auditing of an AI system?
MLOpsAI observabilitymodel auditingAI operations - Question #58Cyber Incident Response
Users report that the output of a generative AI application seems unrelated to the prompts and contains offensive content. A security team investigates and determines that there wa...
session hijackingon-path attackAI application securitygenerative AI attacks - Question #59Security Architecture and Tool Sets
Which of the following is used to train an AI model with unstructured data?
AI model trainingfine-tuningunstructured dataML techniques - Question #60Threat Management
A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system. Which of the following actions sh...
threat modelingMITRE ATLASAI threat landscapeattack path analysis - Question #61Threat Management
Which of the following is the most impactful security risk associated with the use of a generative AI chatbot?
data leakagegenerative AI riskschatbot securityAI security risks - Question #62Cyber Incident Response
When should containment occur during the incident response lifecycle?
incident response lifecyclecontainmenteradicationIR phases - Question #63Threat Management
Which control BEST prevents attackers from harvesting password hashes during lateral movement?
credential harvestinglateral movementpass-the-hashcredential guarding - Question #64Threat Management
Which techniques belong to the MITRE ATT&CK Command-and-Control phase? (Choose two.)
MITRE ATT&CKcommand and controlbeaconingcovert channels - Question #65Threat Management
Which log type is MOST useful for detecting DNS tunneling?
DNS tunnelingDNS query logslog analysisthreat detection - Question #66Security Architecture and Tool Sets
An organization is developing and implementing AI features into a customer service application. Which of the following practices should the organization put the place before releas...
AI securitydata maskingPII protectionpre-release testing - Question #67Threat Management
An internal user enters a client credit card number into an internal generative machine learning (ML) model: #User prompt: Customer Jane Doe has a new credit card that she wants to...
prompt injectionLLM securityguardrailsAI threats - Question #68Threat Management
A security alert triggers an agentic system. An analyst notices the following payload in the logs" The alert includes multiple shell commands that are not typically run as part of...
agentic AIprompt injectionshell command injectionallowlist controls - Question #69Security Architecture and Tool Sets
A global security operations center (SOC) wants to adapt and leverage the strength of AI in order to enhance its security operations. Which of the following is the best way to enha...
AI in SOCalert summarizationsecurity operationsAI automation - Question #70Threat Management
An attacker successfully completes a denial-of-service (DoS) attack through the context window of an AI system. Thousands of characters are obfuscated and hidden behind an emoji. W...
context window attackAI DoSobfuscationprompt filter - Question #71Security Architecture and Tool Sets
An AI architect reviews AI utilization and wants to improve the user experience. Which of the following should the architect review within the logs?
AI monitoringmodel accuracyAI optimizationperformance metrics - Question #72Security Architecture and Tool Sets
A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the que...
one-shot promptingprompt engineeringfew-shot learningAI techniques - Question #73Threat Management
A line of business wants to onboard an application that uses a custom AI model for employee assessments. The Chief Information Officer (CIO) agrees to allow the engagement to proce...
AI threat modelingMITRE ATLASadversarial AIthreat framework - Question #74Threat Management
A security analyst finds that the AI system is under a denial-of-wallet attack. Which of the following should the analyst enforce to protect the company? (Choose two.)
denial-of-walletAPI rate limitingoutput token controlsAI security - Question #75Security Architecture and Tool Sets
A financial organization implements a new AI-based fraud detection system to flag suspicious transactions. A security analyst discovers that it occasionally blocks legitimate trans...
fraud detectionmodel retrainingfalse positivesAI optimization - Question #76Security Architecture and Tool Sets
A security operations center (SOC) analyst needs to automate multiple security tasks by breaking them down into smaller parts. Which of the following AI tools is the best for this...
agentic AItask automationSOC automationAI tools - Question #77Security Architecture and Tool Sets
Which of the following responsible AI standards refers to a principle that clearly states the reasons behind the decisions for a particular conclusion?
responsible AIexplainabilityAI ethicsAI principles - Question #78Vulnerability Management
A web server shows signs of SQL injection. Which control BEST prevents this?
SQL injectioninput validationweb application securityOWASP - Question #79Security Architecture and Tool Sets
Which tool prevents unauthorized system file modifications?
file integrity monitoringFIMsystem integritysecurity tools - Question #80Security Architecture and Tool Sets
What is the PRIMARY purpose of an MSSP for small businesses?
MSSPmanaged securityoutsourced monitoringthreat detection - Question #81Vulnerability Management
Which methods identify vulnerabilities BEFORE deployment? (Choose two.)
static code analysisdesign reviewpre-deployment securityvulnerability assessment - Question #82Security Architecture and Tool Sets
A cybersecurity analyst wants to choose a machine learning (ML) model to classify log entries while providing the best explainability. Which of the following models should the anal...
machine learningexplainabilitydecision treeslog classification - Question #83Security Architecture and Tool Sets
Which of the following is the primary purpose of validating data for an AI system?
AI data validationbias preventiondata qualitymodel integrity - Question #84Security Architecture and Tool Sets
A manufacturing company wants to use AI within its operations to improve the efficiency and accuracy of its processes. Which of the following should the organization do first to en...
AI adoptionorganizational planningAI governancebusiness objectives - Question #85Security Architecture and Tool Sets
Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization. Which of the following should be implemented?
AI chatbotresponse confidenceLLM performancehallucination mitigation - Question #86Threat Management
A security consultant needs to detect attacks across a large language model (LLM) firewall. Which of the following techniques should the consultant use?
LLM firewallsignature matchingattack detectionAI security - Question #87Threat Management
Which of the following is most resistant to AI manipulation?
AI manipulationattack surface reductionAI robustness - Question #88Threat Management
An organization recently developed an AI-powered product and discovers that it is vulnerable to attacks in which malicious actors can alter the input, causing the system to recomme...
adversarial inputguardrailsAI manipulationmodel security - Question #89Threat Management
An IT company implements an adaptable chatbot that learns from user prompts. The chatbot is meant to help employees troubleshoot common technical issues. Based on the following: [U...
prompt injectionguardrailsdata poisoningchatbot security - Question #90Security Architecture and Tool Sets
Which of the following is required first in order to send a prompt query and response in a language model (LLM) system when authentication is enabled?
LLM authenticationendpoint access controlAPI gatewayaccess management - Question #91Threat Management
Global IPs attempt logins against thousands of accounts with known breached credentials. What attack is occurring?
credential stuffingauthentication attacksaccount takeoverbreached credentials - Question #92Security Architecture and Tool Sets
What control reduces the impact radius when a single host is compromised?
network segmentationlateral movementblast radiuscontainment - Question #93Threat Management
A company wants to detect abnormal insider activity based on historical logs. Which technology is BEST?
UEBAinsider threatbehavioral analyticsanomaly detection - Question #94Cyber Incident Response
Which IR document defines who must be contacted during a breach and within what timeframe?
incident responsecommunications planbreach notificationIR documentation - Question #95Vulnerability Management
A detection engineering team wants to use AI to automatically prevent vulnerable code from reaching production. Which of the following is the most effective way to accomplish this...
CI/CD securityLLM integrationDevSecOpscode vulnerability prevention - Question #96Vulnerability Management
A penetration tester is assessing the controls of a deployed AI system that is designed to search and return the contents of files. The tester runs the following: Which of the foll...
least privilegeAI system securityservice accountprivilege reduction - Question #97Threat Management
A customer-facing, AI-powered chatbot has been jailbroken through prompt injections. As a result, the AI model is offering a 99% discount on the purchase of a new vehicle. Which of...
prompt injectionjailbreakingguardrailsLLM robustness - Question #98Security Architecture and Tool Sets
User experience is declining since the launch of a large language model (LLM) in internal networks. Which of the following should be the highest priority for the prompt engineers?
LLM quality controlprompt engineeringuser experiencemodel performance - Question #99Vulnerability Management
A data set containing medical information is put into a machine learning (ML) model that is designed to predict specific illnesses for a population. In the process of verifying the...
AI biasmodel fairnesshealthcare AIpopulation representation