Pre-Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

CY0-001 Questions and Answers

Question # 6

A security analyst notices that regardless of user-submitted prompts, an AI model always returns unsanitized responses. These responses are then passed to multiple plug-ins. The analyst is concerned with the potential security implications.

Which of the following Open Worldwide Application Security Project (OWASP) categories addresses this vulnerability?

A.

Misinformation

B.

Prompt injection

C.

Unbounded consumption

D.

Improper output handling

Full Access
Question # 7

A security analyst needs to conduct a security assessment of the output from an AI-enabled development tool.

Which of the following should the analyst do first?

A.

Remove hard-coded secrets from the source code.

B.

Enforce strict access controls for code repositories.

C.

Enable sensitive data discovery on code repositories.

D.

Perform a source code review.

Full Access
Question # 8

A SOC team has an AI agent that performs web searches and calls to the SOAR solution. The team is concerned about enterprise uptime and case resolution time.

Which of the following is the most appropriate use of the AI agent?

A.

To analyze and contain offending users or hosts using SOAR playbooks

B.

To perform research using open-source intelligence to enrich the alerts

C.

To aggregate SOC metrics and generate reports for the leadership team

D.

To create tabletop exercises so the team can increase its incident response speed

Full Access
Question # 9

A security alert triggers an agentic system. An analyst notices the following payload in the logs. The alert includes multiple shell commands that are not typically run as part of any hardening:

Question # 9

Which of the following is the most effective control to implement?

A.

Adding logic that includes approved strings before running the shell commands

B.

Deprecating model usage and retaining the model with safer parameters

C.

Modifying the application to ignore the SECURITY_UPDATE tag

D.

Using only approved libraries when interacting with agentic systems

Full Access
Question # 10

Which of the following is the primary security risk when deploying AI models in production?

A.

Graphics processing unit (GPU) acceleration

B.

Model overfitting

C.

Model encryption

D.

Data exposure

Full Access
Question # 11

A human resources officer is using AI to evaluate resumes and help select candidates that meet minimum criteria. To improve the results, the human resources officer adjusts the query parameters and includes an example resume that matches a successful candidate.

Which of the following best describes this query?

A.

Distillation

B.

Prompt template

C.

One-shot prompting

D.

System role

Full Access
Question # 12

A short AI-generated video shows a celebrity ' s likeness talking about a fake public security event.

Which of the following was used to create this video?

A.

Statistical analysis

B.

Convolutional neural network

C.

Machine learning (ML) classifier

D.

Random forest

Full Access
Question # 13

A company deploys an internet-facing chatbot using RAG. Logs show that an administrator can retrieve employee names and usernames while an employee receives ' information not available. ' Which of the following is reducing the risk of sensitive data exposure in this scenario?

A.

Data access controls

B.

Model-specific guardrails

C.

Rate limiting

D.

Prompt templates

Full Access
Question # 14

Customer feedback for an AI chatbot has a high-rate of non-answers, which is causing higher central processing unit (CPU) utilization.

Which of the following should be implemented?

A.

Guardrails

B.

Response confidence level

C.

Prompt logging

D.

Cost monitoring

Full Access
Question # 15

A security administrator sees suspicious queries on AI logs.

Which of the following should the administrator implement to address this issue?

A.

Prompt firewalls

B.

Data size

C.

Rate limit

D.

Agentic AI

Full Access
Question # 16

A security administrator wants to prevent prompt injection attacks and ensure responses have sanitized output.

Which of the following provides a primary compensating control for these requirements?

A.

Least privilege

B.

Encryption

C.

A large language model (LLM) firewall

D.

Rate limiting

Full Access
Question # 17

An airline corporation wants to implement a chatbot application using a large language model (LLM) so its customers can ask questions and receive answers about flight details and have the option to upload files.

Which of the following security controls should the airline use to protect against malicious input and unauthorized use beyond the service-level agreement? (Choose two.)

A.

Prompt guardrails

B.

Role-based access controls

C.

Firewall rules

D.

Model token quotas

Full Access
Question # 18

A line of business wants to onboard an application that uses a custom AI model for employee assessments. The Chief Information Officer (CIO) agrees to allow the engagement to proceed but first wants a threat model.

Which of the following is the most appropriate to use for an AI threat model?

A.

Responsible AI

B.

Adversarial Threat Landscape for AI Systems (ATLAS)

C.

Organization for Economic Co-operation and Development (OECD)

D.

International Organization for Standardization (ISO)

Full Access
Question # 19

A company uses human review for software development validation and wants to add another validation layer.

Which of the following should a security administrator use to accomplish this task?

A.

AI-assisted approval

B.

Low-code plug-in

C.

Automated rollback

D.

Regression testing

Full Access
Question # 20

A cybersecurity administrator needs a security mechanism that can validate input.

Which of the following controls should the administrator use?

A.

Prompt firewall

B.

Rate limits

C.

Token limits

D.

Input quantity

Full Access
Question # 21

Which of the following is the most impactful security risk associated with the use of a generative AI chatbot?

A.

Overly permissive access

B.

Data leakage

C.

Weak encryption

D.

Model validation

Full Access
Question # 22

A security analyst is preparing a presentation for the sales team that describes the most common vulnerabilities that are specific to AI applications.

Which of the following is the best source for the analyst to consult?

A.

International Organization for Standards (ISO) 27001

B.

Common Weakness Enumeration (CWE)

C.

Open Worldwide Application Security Project (OWASP)

D.

National Institute of Technologies Risk Management Framework (NIST-RMF)

Full Access
Question # 23

User experience is declining since the launch of a large language model (LLM) in internal networks.

Which of the following should be the highest priority for the prompt engineers?

A.

Customer success management

B.

Sales life cycle

C.

Quality control

D.

Business objectives

Full Access
Question # 24

A cybersecurity analyst must use pattern recognition on a data set containing unstructured data.

Which of the following models is the best for this task?

A.

Long short-term memory

B.

Convolutional neural network

C.

Decision tree

D.

Logistic regression

Full Access
Question # 25

A cybersecurity analyst wants to choose a machine learning (ML) model to classify log entries while providing the best explainability.

Which of the following models should the analyst use?

A.

Large language model (LLM)

B.

Neural networks

C.

Decision trees

D.

Generative adversarial network (GAN)

Full Access
Question # 26

A large number of employees receive a video message in which the company ' s CEO states that the company will be filing for bankruptcy. After an investigation, it was discovered that the CEO did not send this message.

Which of the following is this scenario an example of?

A.

On-path attack

B.

Phishing

C.

Deepfake

D.

Social engineering

Full Access
Question # 27

Which of the following is a key principle of responsible AI systems?

A.

Using protected data for training

B.

Ensuring transparency and explainability

C.

Operating with human-in-the-loop

D.

Maximizing model security

Full Access
Question # 28

A disgruntled employee changed the company policies that a chatbot references in order to create confusion and disrupt the business.

Which of the following AI-generated vulnerabilities is the employee exploiting?

A.

Data reduction

B.

Data masking

C.

Data poisoning

D.

Data leaking

Full Access
Question # 29

Which of the following is used to train an AI model with unstructured data?

A.

Statistical learning

B.

Fine-tuning

C.

Supervised learning

D.

Reinforcement training

Full Access
Question # 30

As a compliance requirement, a large language model (LLM) application requires setting up guardrails.

Which of the following resources is most appropriate to use?

A.

Retrieval-augmented generation (RAG)

B.

Open Worldwide Application Security Project (OWASP)

C.

LLM libraries

D.

Security incident and event management (SIEM)

Full Access
Question # 31

Which of the following roles best supports the implementation of AI governance, risk, and compliance (GRC)? (Choose two.)

A.

Desktop specialist

B.

Data scientist

C.

Software developer

D.

Security architect

E.

Security operations center (SOC) analyst

F.

Network engineer

Full Access
Question # 32

Which of the following helps end users within an organization the most in safeguarding against the risk of AI-related non-compliance?

A.

AI center of excellence

B.

Policies and procedures

C.

Implementing data loss prevention

D.

Enabling multifactor authentication (MFA) for access

Full Access
Question # 33

A security architect performs threat modeling of an AI system. The architect needs to determine which attacks can be performed against the system.

Which of the following actions should the architect take next?

A.

Leverage a large language model (LLM) to map likely attack paths based on the code base.

B.

Quantify the risk of known vulnerabilities identified in the AI system.

C.

Identify trust boundaries and perform threat modeling with Open Worldwide Application Security Project (OWASP) Top 10.

D.

Analyze MITRE Adversarial Threat Landscape for AI Systems (ATLAS) for tactics, techniques, and procedures (TTPs).

Full Access
Question # 34

A management team is concerned about an unexpected cost increase for a public-facing AI chatbot.

Which of the following should a security administrator examine first to determine the root cause?

A.

Firewall logs

B.

Web application firewall (WAF) rules

C.

Vector database input/output operations per second performance

D.

Model token usage

Full Access
Question # 35

Instructions: Click the (+) to assign each threat category into its appropriate framework.

An architect is modeling an agentic system to meet security standards.

Question # 35

Full Access
Question # 36

A company is adopting AI and wants to create policies and procedures that include a structure for evaluating, publishing, and approving patterns for AI usage.

Which of the following should the company establish to meet this goal?

A.

AI center of excellence

B.

AI legal affairs office

C.

AI audit department

D.

AI data science division

Full Access
Question # 37

Which of the following is required first in order to send a prompt query and response in a language model (LLM) system when authentication is enabled?

A.

Front-end web proxy gateway

B.

Endpoint access control

C.

Application programming interface gateway

D.

Back-end access gateway

Full Access