CertSafari

    Free CompTIA SecAI+ Sample Questions

    35 free sample questions from our bank of 348+, covering every exam domain, with answers and detailed explanations. Updated October 2026.

    Subdomain 1.2: Explain the importance of data security in relation to AI.

    1.A malware-classification team has only a handful of samples from a rare ransomware family, and collecting more is not possible. Which technique can expand the training set from the existing samples?

    1. A.Data cleansing: drop the rare-family samples as outliers so the dataset only contains well-represented categories
    2. B.Data verification: re-check each rare sample's checksum so the training set contains the same samples with added trust
    3. C.Data augmentation: derive label-preserving variants of existing samples, such as padded or reordered binaries
    4. D.Data lineage: log the transformations of every rare sample so reviewers can see exactly where the samples came from
    Show answer & explanation

    Correct answer: C — Data augmentation: derive label-preserving variants of existing samples, such as padded or reordered binaries

    • A. Removing rare samples as outliers would shrink the family's representation further, the opposite of the goal of expanding the available training data.
    • B. Verification confirms authenticity and integrity of existing samples but produces no additional examples, so the dataset stays just as small.
    • C. Augmentation creates new training examples from existing ones through label-preserving transformations. Teams should still review the variants, since errors or leaked content in the originals are inherited.
    • D. Lineage tracking documents history and transformations; it does not generate new samples, so the rare family remains underrepresented.

    Subdomain 1.2: Explain the importance of data security in relation to AI.

    2.A phishing-detection model is trained on a corpus that is 98% legitimate email and 2% phishing. It reports 98% accuracy but misses nearly every phishing message. Which data processing step best addresses the root cause?

    1. A.Data balancing: oversample phishing, undersample legitimate mail, or weight classes so both labels shape training
    2. B.Data cleansing: strip HTML tags and signature blocks from every message so the text fields are uniformly formatted
    3. C.Watermarking: embed a hidden marker in the phishing messages so the model can recognize them during later retraining
    4. D.Data verification: validate sender domains of each legitimate email so only authenticated messages remain in the corpus
    Show answer & explanation

    Correct answer: A — Data balancing: oversample phishing, undersample legitimate mail, or weight classes so both labels shape training

    • A. The model learned to predict the majority class because the labels are heavily skewed. Balancing the classes through resampling or class weights lets the minority phishing class shape the model.
    • B. Format cleanup improves consistency of text but leaves the 98 to 2 skew in place, so the model would still favor the majority class.
    • C. Watermarks identify content origin; adding them to phishing messages does not change class proportions and could introduce a shortcut feature the model learns.
    • D. Validating sender domains checks authenticity of legitimate mail, but it does not change the ratio between classes that causes the missed detections.

    Subdomain 1.3: Explain the importance of security throughout the life cycle of AI.

    3.A developer downloads a pretrained image model from a public model hub to fine-tune for badge recognition. The file is a serialized pickle archive from an unknown publisher. Which step best protects the model development stage?

    1. A.Load the archive directly on the production training cluster, since fine-tuning will overwrite the weights that came with the download anyway
    2. B.Use a trusted publisher, verify the file hash, and scan the artifact for embedded code before loading it in an isolated sandbox
    3. C.Rename the file and store it in the team's artifact repository so that auditors see a consistent naming convention for all models
    4. D.Quantise the model to a smaller size first, because reducing the precision of the weights removes any malicious payload it contains
    Show answer & explanation

    Correct answer: B — Use a trusted publisher, verify the file hash, and scan the artifact for embedded code before loading it in an isolated sandbox

    • A. Incorrect: fine-tuning overwrites weights but the malicious code in a serialized file runs at load time, before any training begins.
    • B. Correct: pretrained artifacts are an AI supply chain risk, and pickle files can execute arbitrary code on load, so provenance, hash verification, scanning and sandboxing reduce that exposure.
    • C. Incorrect: a naming convention helps organisation but does nothing to confirm the artifact is safe or genuine.
    • D. Incorrect: quantisation changes numeric precision and does not strip out executable payloads in the serialization format.

    Subdomain 1.3: Explain the importance of security throughout the life cycle of AI.

    4.An e-commerce site retrains its ranking model every week using thumbs-up and thumbs-down clicks from users. A security reviewer is concerned about the feedback and iteration stage. What control best reduces the risk?

    1. A.Retrain the model daily instead of weekly so that any biased signals are overwritten quickly by the next batch of user clicks
    2. B.Disable logging of user clicks so that no feedback data exists for an attacker to modify or steal from the training pipeline
    3. C.Increase the learning rate for each retraining run so the model reacts more strongly to the most recent user preferences
    4. D.Validate feedback before retraining, throttle suspicious accounts, and sample entries so manipulation cannot steer the model
    Show answer & explanation

    Correct answer: D — Validate feedback before retraining, throttle suspicious accounts, and sample entries so manipulation cannot steer the model

    • A. Incorrect: retraining more often ingests manipulated feedback faster and offers more opportunities for it to take hold.
    • B. Incorrect: removing the logging eliminates the feedback process entirely, discarding the iteration benefit and not addressing manipulation.
    • C. Incorrect: a higher learning rate makes the model more sensitive to recent, possibly manipulated, data.
    • D. Correct: feedback loops are an input channel an attacker can game, so validating signals, rate limiting suspicious accounts and sampling for review keeps poisoned feedback out of retraining.

    Subdomain 1.1: Compare and contrast various AI types and techniques used in cybersecurity.

    5.A network team collects NetFlow records from thousands of hosts. None of the records are labeled, and the team wants to surface groups of hosts that behave unusually without predefining attack categories. Which technique is most appropriate?

    1. A.Unsupervised learning, such as clustering or anomaly detection, grouping hosts by behavior and flagging outliers with no labeled records
    2. B.Supervised learning, training a classifier on a vendor-supplied list of attack names that must first be attached to every NetFlow record by hand
    3. C.Reinforcement learning, deploying an agent that blocks hosts at random and receives a reward whenever the network stays stable for another hour
    4. D.Fine-tuning, continuing training of a pretrained language model on the raw NetFlow text so it memorizes the typical hosts and their ports
    Show answer & explanation

    Correct answer: A — Unsupervised learning, such as clustering or anomaly detection, grouping hosts by behavior and flagging outliers with no labeled records

    • A. Unsupervised learning discovers patterns in unlabeled data, so clustering and anomaly detection can isolate hosts that deviate from the norm without predefined categories.
    • B. Supervised learning requires labels for each training record. Without labeled flows it cannot be trained, and predefined attack names contradict the goal of discovering unknown behavior.
    • C. Reinforcement learning learns from rewards gained by acting in an environment. It is an action-selection method, not a way to group unlabeled records, and random blocking would cause outages.
    • D. Fine-tuning adapts a pretrained model's weights to a task, usually with curated examples. It does not by itself produce behavioral groupings, and memorizing raw records invites overfitting.

    Subdomain 1.1: Compare and contrast various AI types and techniques used in cybersecurity.

    6.A red team needs realistic synthetic network traffic to test an intrusion detection system without exposing production data. They choose a generative adversarial network (GAN). How does a GAN produce convincing samples?

    1. A.One network creates candidate samples while a second tries to tell them from real traffic, and both improve through that competition
    2. B.A single network predicts the next token in each packet capture, repeatedly appending its guess until a complete synthetic session is assembled
    3. C.A clustering algorithm groups the real flows by similarity and then replays the centroid of each group as if it were a brand-new session
    4. D.An agent receives rewards for each packet that evades the detection system and gradually learns a policy for crafting evasive sessions
    Show answer & explanation

    Correct answer: A — One network creates candidate samples while a second tries to tell them from real traffic, and both improve through that competition

    • A. A GAN pairs a generator with a discriminator. The generator tries to fool the discriminator and the discriminator tries to catch fakes, so each pushes the other to improve.
    • B. Next-token prediction describes autoregressive language models, not GANs. A GAN's defining feature is two competing networks rather than one sequential predictor.
    • C. Clustering summarizes existing data and replaying centroids creates no new variety. GANs learn the data distribution through adversarial training instead.
    • D. Reward-driven policy learning is reinforcement learning. It optimizes evasion behavior rather than learning to generate samples that statistically resemble real traffic.

    Subdomain 1.1: Compare and contrast various AI types and techniques used in cybersecurity.

    7.A developer builds a SOC triage assistant and needs it to always act as a cautious analyst, use a fixed report format, and decline unrelated requests regardless of what individual analysts type. Where should these standing instructions be placed?

    1. A.In the system prompt, which the developer sets once to establish the assistant's role and rules for each conversation
    2. B.In each analyst's user prompt, typed fresh at the start of every query by whichever person is using the assistant
    3. C.In the training run's epoch count, which determines how many times the model repeats the required rules to learn them
    4. D.In a vector of quantized weights that is attached to the prompt to remind the model of its stated constraints
    Show answer & explanation

    Correct answer: A — In the system prompt, which the developer sets once to establish the assistant's role and rules for each conversation

    • A. The system prompt carries persistent developer instructions and role definition that frame every turn, which is what the scenario requires.
    • B. User prompts are supplied by individual users and can vary or omit the rules, so standing guardrails cannot depend on them.
    • C. The epoch count controls passes over training data and cannot encode runtime behavior instructions.
    • D. Quantized weights are a compression artifact of the model itself, not a place to store instructions.

    Domain 2: Securing AI Systems

    Subdomain 2.2: Given a set of requirements, implement security controls for AI systems.

    8.Before releasing a fine-tuned loan-advice model, the security team must show it resists harmful requests and does not leak training data. Which activity satisfies this requirement?

    1. A.Review the infrastructure-as-code templates for the inference cluster to confirm that all storage buckets are encrypted
    2. B.Run a model evaluation using red-team prompts and safety benchmarks, scoring refusal behavior and extraction of memorized data
    3. C.Confirm that the training dataset has been stored in a region matching the company's data residency commitments
    4. D.Increase the batch size during inference so latency stays low while the model handles many safety-related questions
    Show answer & explanation

    Correct answer: B — Run a model evaluation using red-team prompts and safety benchmarks, scoring refusal behavior and extraction of memorized data

    • A. Incorrect. Infrastructure review verifies the hosting environment but does not measure the model's behavior under adversarial prompts.
    • B. Correct. Model evaluation measures behavior against adversarial and safety test sets, producing evidence that the model meets the stated requirements.
    • C. Incorrect. Residency compliance is a data governance matter and says nothing about how the trained model responds to attacks.
    • D. Incorrect. Batch size is a performance setting and does not validate safety or leakage characteristics.

    Subdomain 2.2: Given a set of requirements, implement security controls for AI systems.

    9.Select TWO gateway controls that together reduce the risk of model denial of service and runaway cost on a shared LLM endpoint.(Select 2)

    1. A.Per-client token limits on both prompts and generated output, rejecting or truncating requests that exceed the configured budget
    2. B.A prompt template that places the system instructions before the user's text and delimits the untrusted input section
    3. C.Request rate limits per API key that return HTTP 429 once the allowed number of calls in the time window is exceeded
    4. D.A weekly model evaluation using toxicity benchmarks to confirm that response quality has not degraded over time
    5. E.A response filter that masks credit card numbers and national identifiers before the output returns to the application
    Show answer & explanation

    Correct answers: A, C — Per-client token limits on both prompts and generated output, rejecting or truncating requests that exceed the configured budget; Request rate limits per API key that return HTTP 429 once the allowed number of calls in the time window is exceeded

    • A. Correct. Token limits bound the compute and cost of each request, directly addressing resource exhaustion.
    • B. Incorrect. Templates help against injection but do not cap resource consumption.
    • C. Correct. Rate limits stop a single client from flooding the endpoint and starving other tenants.
    • D. Incorrect. Evaluation tracks quality and safety but does not restrict how much capacity a caller can consume.
    • E. Incorrect. Output masking protects sensitive data and has no effect on request volume or compute use.

    Subdomain 2.2: Given a set of requirements, implement security controls for AI systems.

    10.Which description correctly distinguishes a rate limit from a token limit at an AI gateway?

    1. A.A rate limit restricts how many requests a client may send per time window, while a token limit bounds the size of text processed
    2. B.A rate limit restricts the languages a model may answer in, while a token limit restricts which users may connect
    3. C.A rate limit encrypts requests with a rotating key, while a token limit signs authentication cookies for each session
    4. D.A rate limit measures model accuracy over time, while a token limit measures the number of hallucinations produced
    Show answer & explanation

    Correct answer: A — A rate limit restricts how many requests a client may send per time window, while a token limit bounds the size of text processed

    • A. Correct. Rate limits count requests over time; token limits cap the amount of text, so they address different abuse patterns and are usually combined.
    • B. Incorrect. Neither control concerns language or identity; those are separate policy and access matters.
    • C. Incorrect. Both descriptions confuse the controls with cryptographic functions that they do not perform.
    • D. Incorrect. Accuracy and hallucination rates are evaluation measures, not gateway enforcement controls.

    Subdomain 2.1: Given a scenario, use AI threat-modeling resources.

    11.Testers find that a fine-tuned customer-service model reproduces real customers' phone numbers and addresses when prompted with the start of a stored record. Which OWASP LLM Top 10 risk applies, and what is the best mitigation?

    1. A.Excessive agency; remove the model's access to external tools and require approval for every action it attempts on a customer's behalf
    2. B.Sensitive information disclosure; sanitize and deduplicate fine-tuning data, anonymize personal fields, and filter model outputs for personal data
    3. C.Improper output handling; HTML-encode every response before display so customer records cannot be rendered as active content in the browser
    4. D.Unbounded consumption; apply a daily token limit per authenticated user account so that fewer customer records can be extracted during any single session
    Show answer & explanation

    Correct answer: B — Sensitive information disclosure; sanitize and deduplicate fine-tuning data, anonymize personal fields, and filter model outputs for personal data

    • A. Excessive agency concerns the actions a model can take. The scenario is about memorized personal data in outputs, not tool permissions.
    • B. Sensitive information disclosure covers a model revealing confidential data memorized in training. Scrubbing the training set and filtering outputs reduce what can be extracted.
    • C. Encoding prevents scripts from running when output is rendered. It does not stop the model from revealing real personal data in plain text.
    • D. Token limits bound cost and availability. They only slow extraction rather than remove memorized personal data from the model.

    Subdomain 2.1: Given a scenario, use AI threat-modeling resources.

    12.A team threat-models a retrieval-augmented chatbot. The data-flow diagram shows users calling an API, a retriever reading a vector store, and an LLM answering. External partners also upload documents into the same vector store through a portal. Which finding should the team prioritize?

    1. A.The user-to-API link, because transport encryption is the only trust boundary in a retrieval system where an attacker could interfere with traffic
    2. B.The partner upload path, which crosses a trust boundary and lets untrusted content reach the model through retrieval as poisoned or injected text
    3. C.The LLM's temperature setting, because randomness in generation is the main way an attacker can change what the retriever returns
    4. D.The log retention period, because any threat model of a retrieval system should begin with how long query records are stored on disk
    Show answer & explanation

    Correct answer: B — The partner upload path, which crosses a trust boundary and lets untrusted content reach the model through retrieval as poisoned or injected text

    • A. TLS on the user link matters, but it is not the only boundary. The partner upload path introduces untrusted content that transport encryption does not address.
    • B. Content from outside the organization enters the vector store and is later fed to the model. That boundary crossing exposes the system to data poisoning and indirect prompt injection, so it deserves priority.
    • C. Temperature controls sampling randomness and has no effect on what the retriever returns or on trust boundaries in the architecture.
    • D. Retention is a compliance consideration. A threat model starts from data flows and trust boundaries, not from log storage duration.

    Subdomain 2.3: Given a scenario, implement appropriate access controls for AI systems.

    13.A helpdesk agent only needs to look up ticket status and reset passwords for standard users, but it runs under a service account that can also modify directory groups. What should be done first?

    1. A.Keep the service account and add a system prompt rule telling the agent to avoid editing groups unless a user asks.
    2. B.Increase directory logging verbosity so unexpected group changes made by the agent show up in the weekly review.
    3. C.Replace it with a dedicated identity limited to those two tool actions and scoped to standard-user accounts only.
    4. D.Switch the agent to a model that follows tool instructions more reliably so it makes fewer unwanted directory calls.
    Show answer & explanation

    Correct answer: C — Replace it with a dedicated identity limited to those two tool actions and scoped to standard-user accounts only.

    • A. Prompt rules can be overridden by prompt injection, and the account would still hold the dangerous permission.
    • B. Logging helps detection and forensics but does not prevent an unwanted group change from happening.
    • C. Reducing the agent's credentials to what its task needs addresses excessive agency at the source: even a manipulated agent cannot change groups it has no permission to touch.
    • D. A better instruction-following model lowers error rates but cannot guarantee safe behaviour; the over-broad permission remains exploitable.

    Subdomain 2.3: Given a scenario, implement appropriate access controls for AI systems.

    14.A model endpoint that can be reached only from approved subnets through a private link relies mainly on ______ to limit exposure.

    1. A.network segmentation
    2. B.output filtering
    3. C.prompt templating
    Show answer & explanation

    Correct answer: A — network segmentation

    • A. Network segmentation restricts which networks can open connections to the endpoint, which limits exposure before any authentication occurs.
    • B. Output filtering inspects model responses and does not control which networks can reach the endpoint.
    • C. Prompt templating structures user input to the model and has no effect on network reachability.

    Subdomain 2.4: Given a scenario, implement data security controls for AI systems.

    15.A mobile banking app sends customer questions to a hosted LLM inference API across the public internet. The security team wants to stop eavesdroppers on shared Wi-Fi from reading prompts and responses. Which control meets this requirement?

    1. A.Run the inference service inside a trusted execution environment so memory contents stay hidden from the host OS
    2. B.Enable AES-256 server-side encryption on the storage volume that holds the model weights behind the API endpoint
    3. C.Require TLS 1.3 on the inference endpoint and reject any plaintext HTTP connection attempts from clients
    4. D.Apply format-preserving masking to account numbers inside the prompt text before the app stores the chat history
    Show answer & explanation

    Correct answer: C — Require TLS 1.3 on the inference endpoint and reject any plaintext HTTP connection attempts from clients

    • A. Incorrect: a trusted execution environment protects data in use in memory on the server, not traffic on a shared Wi-Fi link.
    • B. Incorrect: encrypting the volume with model weights protects data at rest on disk and does nothing for packets crossing the network.
    • C. Correct: TLS protects data in transit between client and endpoint, so a network eavesdropper only sees ciphertext.
    • D. Incorrect: masking account numbers changes stored values but the prompts and responses still travel unencrypted over the wire.

    Subdomain 2.4: Given a scenario, implement data security controls for AI systems.

    16.A company ingests internal documents into a shared RAG index that powers a chatbot available to all employees. Some files are marked 'Restricted - Legal' in their metadata. Which control uses those markings to prevent exposure through the chatbot?

    1. A.Reduce the chunk size used during embedding so that each retrieved passage contains less of any single restricted file
    2. B.Enforce classification labels at ingestion and retrieval so restricted files are filtered by user clearance
    3. C.Mask the file names displayed in chatbot citations while still embedding the full text of every document into the index
    4. D.Encrypt the whole vector index with a single key so that every file is protected equally regardless of its sensitivity marking
    Show answer & explanation

    Correct answer: B — Enforce classification labels at ingestion and retrieval so restricted files are filtered by user clearance

    • A. Incorrect: smaller chunks still return restricted content and do nothing to apply the classification policy.
    • B. Correct: classification labels drive policy decisions, so ingestion and retrieval can exclude or filter content based on the label and the user's clearance.
    • C. Incorrect: masking file names leaves the restricted text embedded and retrievable in answers.
    • D. Incorrect: one key for the whole index treats all files identically and does not use the labels to limit what the chatbot returns.

    Subdomain 2.4: Given a scenario, implement data security controls for AI systems.

    17.In which state is training data when it is loaded into a GPU server's memory and actively being processed by a model-training job?

    1. A.In archive, which is protected by retention rules that delete the dataset once the training job has finished
    2. B.At rest, which is protected by volume encryption and managed keys applied to the storage holding the dataset
    3. C.In transit, which is protected by TLS between the storage service and the server that reads the data
    4. D.In use, which is protected by confidential computing rather than by disk or network encryption
    Show answer & explanation

    Correct answer: D — In use, which is protected by confidential computing rather than by disk or network encryption

    • A. Incorrect: archive is not one of the three standard encryption states, and retention rules do not protect active processing.
    • B. Incorrect: at rest refers to data sitting on persistent storage, not data held in memory during processing.
    • C. Incorrect: in transit describes data moving across a network, which ended once the data reached the server.
    • D. Correct: data actively being processed in memory is in use, and TEEs or confidential computing are the matching protection.

    Subdomain 2.5: Given a scenario, implement monitoring and auditing for AI systems.

    18.A team logs every prompt and completion from a medical-intake assistant for debugging. A privacy review finds patient names and national ID numbers in the log index. What should the team implement to fix the logging pipeline?

    1. A.Extend log retention to seven years so that auditors can see exactly what was captured for every patient session
    2. B.Restrict the log index to read-only access for the on-call engineers and keep every stored field unchanged
    3. C.Add a sanitization step that redacts or tokenizes PII and secrets before records are written to the log store
    4. D.Compress the logs with gzip and move them to a different storage account in the same region each night
    Show answer & explanation

    Correct answer: C — Add a sanitization step that redacts or tokenizes PII and secrets before records are written to the log store

    • A. Longer retention would keep the exposed identifiers for years, increasing rather than reducing the privacy risk.
    • B. Read-only access limits who can edit entries, but the names and ID numbers remain readable in every stored field.
    • C. Log sanitization removes or tokenizes sensitive values before persistence, so debugging data stays useful without storing raw identifiers. Applying it in the pipeline prevents the exposure at the source.
    • D. Compression and relocation change the storage format and location, but the sensitive data is still present in clear text.

    Subdomain 2.5: Given a scenario, implement monitoring and auditing for AI systems.

    19.During a quarterly access audit of an AI platform, a reviewer finds former contractors still hold permissions to query a model trained on confidential data and to download its logs. Which action is best?

    1. A.Remove stale accounts, enforce role-based least privilege, and schedule recurring access reviews that retain evidence
    2. B.Leave the accounts active but add a banner reminding contractors to follow acceptable use rules on each login to the portal
    3. C.Move the confidential training data into a public bucket so the permissions on the model no longer matter for contractors
    4. D.Ask the contractors by email to confirm whether they still require access and wait for their replies before changing any permissions
    Show answer & explanation

    Correct answer: A — Remove stale accounts, enforce role-based least privilege, and schedule recurring access reviews that retain evidence

    • A. Revoking stale access, applying role-based least privilege and reviewing entitlements on a schedule closes the gap and produces evidence for auditors. This is the access element of AI auditing.
    • B. A banner does not remove permissions, so former contractors could still query the model and download logs.
    • C. Publishing confidential data would create a far worse exposure and is not a control.
    • D. Relying on the contractors' own replies leaves access open during the wait and is not an independent verification.

    Subdomain 2.6: Given a scenario, analyze the evidence of an attack and suggest compensating controls for AI systems.

    20.A public image-classification API returns the full probability vector for each query. A security analyst sees an account submitting thousands of crafted inputs and later finds reconstructed approximations of training faces posted online. Which compensating control most directly limits this model inversion attack?

    1. A.Require multi-factor authentication for administrators who deploy new model versions to the production inference cluster
    2. B.Return only the top predicted label, round or suppress confidence scores, and apply differential privacy during training
    3. C.Increase the training dataset size by scraping additional public images so each person is a smaller share of the data
    4. D.Add a content filter that blocks uploads containing profanity or explicit imagery before they reach the classifier
    Show answer & explanation

    Correct answer: B — Return only the top predicted label, round or suppress confidence scores, and apply differential privacy during training

    • A. Incorrect. MFA for deployers protects the release process, not the information exposed through query responses.
    • B. Correct. Detailed confidence vectors leak gradient-like information; limiting output granularity and adding differential privacy reduces what an attacker can reconstruct.
    • C. Incorrect. Scraping more images does not hide per-query confidence output and adds provenance and privacy concerns of its own.
    • D. Incorrect. A profanity or explicit-content filter addresses abusive uploads, not the reconstruction of training data from probabilities.

    Subdomain 2.6: Given a scenario, analyze the evidence of an attack and suggest compensating controls for AI systems.

    21.A data science team notices their model reports markedly higher confidence on records that were part of its training set than on similar unseen records, and an external researcher demonstrates determining whether a given patient record was in the training data. Which attack does this evidence describe, and what is a suitable mitigation?

    1. A.Model theft; throttle high-volume queries and watermark the model so a stolen copy can later be identified
    2. B.Output integrity attack; sign each response and verify the signature in the client application before it is displayed
    3. C.Membership inference; reduce overfitting with regularization and differential privacy, and limit confidence values
    4. D.Model skewing; validate user feedback before it reaches the retraining pipeline and cap submissions per account
    Show answer & explanation

    Correct answer: C — Membership inference; reduce overfitting with regularization and differential privacy, and limit confidence values

    • A. Incorrect. Model theft aims to copy the model's behavior or weights, not to determine whether a particular record was used for training.
    • B. Incorrect. Output integrity attacks tamper with responses in flight or at rest; here the responses were genuine but leaked membership.
    • C. Correct. Confidence gaps between members and non-members enable membership inference, and overfitting reduction plus differential privacy narrows that signal.
    • D. Incorrect. Model skewing manipulates what the model learns from feedback, rather than revealing whether a record was in training data.

    Subdomain 2.6: Given a scenario, analyze the evidence of an attack and suggest compensating controls for AI systems.

    22.A SaaS vendor's proprietary sentiment model is exposed through a paid API. Monitoring shows one new account sending 400,000 systematically varied queries over two days, and a competitor soon launches a product with nearly identical predictions. Which combination of controls best mitigates this model theft pattern?

    1. A.Moving inference to a larger GPU instance type so the endpoint sustains the heavier request load without latency spikes
    2. B.Per-key rate limits and quotas, query-pattern anomaly detection, and access controls binding each key to a verified customer
    3. C.Retraining the production model nightly with fresh data so any surrogate model built from earlier responses becomes obsolete
    4. D.Adding a prompt template that rewrites every incoming query into a standard format before the model processes it
    Show answer & explanation

    Correct answer: B — Per-key rate limits and quotas, query-pattern anomaly detection, and access controls binding each key to a verified customer

    • A. Incorrect. More GPU capacity helps availability but makes bulk extraction easier rather than harder.
    • B. Correct. Extraction attacks depend on high-volume systematic querying, so quotas, anomaly detection and authenticated, attributable keys raise the cost and expose the activity.
    • C. Incorrect. Nightly retraining is costly and still leaves the same extraction route open; the attacker simply queries again.
    • D. Incorrect. Standardizing query format does not limit how many queries an attacker sends or who sends them.

    Domain 3: AI-assisted Security

    Subdomain 3.1: Given a scenario, use AI-enabled tools to facilitate security tasks.

    23.An architect gives an AI assistant a data flow diagram of a new customer portal and asks for threats by STRIDE category. What is the right way to use the result?

    1. A.Accept the list as the complete and final threat model since the assistant covered all six STRIDE categories for each component
    2. B.Discard the output because threat modeling can only be done in a workshop and generated content cannot inform any decision
    3. C.Use the list only after the portal is in production, because threats cannot be identified before real traffic exists to analyze
    4. D.Treat it as a starting list of threats, then have security staff validate, prioritize and add business-specific risks it missed
    Show answer & explanation

    Correct answer: D — Treat it as a starting list of threats, then have security staff validate, prioritize and add business-specific risks it missed

    • A. Coverage of categories does not mean completeness or accuracy, because the model lacks full knowledge of the environment.
    • B. AI-generated threats are a useful input. Rejecting them entirely forgoes the speed benefit without good reason.
    • C. Threat modeling is most valuable at design time, before the system is built and attackers can exploit it.
    • D. Correct. AI can accelerate brainstorming in threat modeling, but experts must validate relevance and fill gaps based on the real system and context.

    Subdomain 3.1: Given a scenario, use AI-enabled tools to facilitate security tasks.

    24.A security team plans to let analysts use a generative AI chatbot for investigation support. Which TWO controls best reduce the data exposure risk of this deployment?(Select 2)

    1. A.Allow analysts to choose any free public chatbot they prefer, provided they delete their chat history every week
    2. B.Provide a sanctioned enterprise chatbot with contractual no-training terms and tenant isolation for analyst use
    3. C.Instruct analysts to type prompts in all lowercase so that logging systems cannot identify any customer names
    4. D.Apply automatic redaction of secrets, personal data and internal hostnames to prompts before they leave the network
    5. E.Increase the chatbot's response length limit so analysts receive more detailed answers in a single reply
    Show answer & explanation

    Correct answers: B, D — Provide a sanctioned enterprise chatbot with contractual no-training terms and tenant isolation for analyst use; Apply automatic redaction of secrets, personal data and internal hostnames to prompts before they leave the network

    • A. Deleting history later does not undo disclosure, and unsanctioned tools bypass the organization's data handling controls.
    • B. Correct. An approved enterprise deployment with data-handling terms keeps submitted content from being used to train shared models or leak to other tenants.
    • C. Letter case has no effect on whether sensitive data is exposed or logged.
    • D. Correct. Redaction or masking before submission reduces what sensitive content can ever be disclosed, whatever the provider does afterward.
    • E. Response length does not change what data is submitted and is unrelated to exposure risk.

    Subdomain 3.2: Explain how AI enables or enhances attack vectors.

    25.A company hires a remote developer after a video interview. Weeks later it discovers the person's face and voice were synthesized in real time to hide a different identity, and the account was used to steal source code. Which hiring-process change would best reduce this risk?

    1. A.Allowing candidates to turn off their cameras so the recruiter can avoid receiving visual media that might be manipulated
    2. B.Moving all interviews to audio-only calls because voice samples are harder to synthesize than live video streams
    3. C.Relying on the length of the candidate's employment history as sufficient proof that the identity presented is genuine
    4. D.Verifying identity with government ID checks and an in-person or notarized step before granting repository access
    Show answer & explanation

    Correct answer: D — Verifying identity with government ID checks and an in-person or notarized step before granting repository access

    • A. Incorrect: removing video weakens verification and still leaves the voice open to cloning.
    • B. Incorrect: voice cloning is mature and convincing, so audio-only interviews are not safer than video.
    • C. Incorrect: an employment history is just text that the attacker can fabricate, so it does not prove who is on screen.
    • D. Correct: identity proofing with documents and a physical or notarized step ties the person to a verifiable real identity that synthetic media cannot fake.

    Subdomain 3.2: Explain how AI enables or enhances attack vectors.

    26.A company's AI-assisted exploit tool takes a published CVE description and a target's version banner, then produces a working proof-of-concept exploit in minutes. Which concern does this create for defenders?

    1. A.Vulnerability disclosure becomes unnecessary, since exploits are produced regardless of whether a CVE entry is published
    2. B.The window between vulnerability disclosure and weaponized exploitation shrinks, so patching must be faster
    3. C.Penetration testing is no longer allowed, because AI-generated proof-of-concepts are legally treated as malware
    4. D.Version banners become the only way for defenders to identify assets, so banners must be exposed to every scanner online
    Show answer & explanation

    Correct answer: B — The window between vulnerability disclosure and weaponized exploitation shrinks, so patching must be faster

    • A. Incorrect: public advisories still help defenders, and the tools described here depend on them.
    • B. Correct: automated exploit generation compresses time-to-exploit, so organizations need rapid patch cycles and compensating controls.
    • C. Incorrect: authorized testing remains lawful and valuable; the point is that defenders must respond more quickly.
    • D. Incorrect: exposing banners helps attackers fingerprint versions, so removing or masking them is recommended.

    Subdomain 3.3: Given a scenario, use AI to automate security tasks.

    27.After a new WAF rule set is deployed, the application error rate jumps to 5%. The team wants the pipeline to restore service without waiting for a person. Which configuration achieves this?

    1. A.Retain deployment logs for ninety days so engineers can reconstruct the earlier configuration manually after the report
    2. B.Restrict deployments to the weekly maintenance window so a failed rule set affects fewer users during business hours
    3. C.Configure health checks with error-rate thresholds that trigger automatic redeployment of the previous good version
    4. D.Add a manual approval gate before every deployment so a person reads the rule set diff before it is pushed
    Show answer & explanation

    Correct answer: C — Configure health checks with error-rate thresholds that trigger automatic redeployment of the previous good version

    • A. Log retention helps forensics but does not restore service, and manual reconstruction is slow and error-prone.
    • B. A maintenance window limits timing but does nothing to detect failure or revert once the faulty rules are live.
    • C. Automated rollback depends on monitored thresholds that detect a bad release and redeploy the last good artifact immediately.
    • D. A pre-deployment approval gate is a preventive control; it cannot revert a release that has already degraded production.

    Subdomain 3.3: Given a scenario, use AI to automate security tasks.

    28.Business units are building no-code automations that connect to corporate mailboxes and file shares through OAuth connectors. Which measure best reduces the security risk?

    1. A.Inventory the automations, review connector scopes for least privilege, and restrict approved connectors by policy
    2. B.Let each builder authorize full-mailbox permissions, since no-code logic cannot contain any code vulnerabilities
    3. C.Disable the platform's audit logging because flow run histories duplicate data already retained in the mailboxes
    4. D.Ask builders to place connector credentials in a shared spreadsheet so security staff can inspect them during reviews
    Show answer & explanation

    Correct answer: A — Inventory the automations, review connector scopes for least privilege, and restrict approved connectors by policy

    • A. Visibility and scope control address the main no-code risk: unmanaged automations holding broad access to sensitive data.
    • B. No-code flows can still over-privilege connectors and leak data; absence of code does not remove access risk.
    • C. Run histories show what automations did, so disabling them removes accountability and incident visibility.
    • D. Collecting credentials in a spreadsheet exposes them to anyone with access and violates secret management practice.

    Subdomain 3.3: Given a scenario, use AI to automate security tasks.

    29.What primarily distinguishes an AI agent from a fixed SOAR playbook script?

    1. A.The agent plans toward a goal and picks tools dynamically from intermediate results, while a script follows fixed steps
    2. B.The agent runs without any credentials because it reasons about permissions, while scripts must authenticate to systems
    3. C.The agent executes only on a fixed cron schedule, while scripts react to events in real time as they arrive
    4. D.The agent cannot call external APIs, while scripts may integrate with any tool the security team has approved
    Show answer & explanation

    Correct answer: A — The agent plans toward a goal and picks tools dynamically from intermediate results, while a script follows fixed steps

    • A. Goal-directed planning and dynamic tool selection give agents flexibility, and also create the need for guardrails and oversight.
    • B. Agents need credentials to act on systems just as scripts do; reasoning does not replace authorization.
    • C. Agents can be event-driven, and scripts can be scheduled; triggering is not the defining difference.
    • D. Agents commonly call APIs and tools, which is exactly what gives them capability and risk.

    Domain 4: AI Governance, Risk, and Compliance

    Subdomain 4.1: Explain organizational governance structures that support AI.

    30.In a hub-and-spoke AI operating model, what is the role of the central AI Center of Excellence acting as the hub?

    1. A.Provide shared standards and reference architectures while practitioners embedded in business units apply them locally
    2. B.Own every model-training job directly so that business units never handle data, code, or deployment pipelines themselves
    3. C.Act as the independent assurance function that audits each unit's AI controls and reports findings directly to the board
    4. D.Maintain the corporate firewall rules and network segmentation that separate AI workloads from the remaining enterprise systems
    Show answer & explanation

    Correct answer: A — Provide shared standards and reference architectures while practitioners embedded in business units apply them locally

    • A. The hub provides common standards and expertise and the spokes embed practitioners who apply them to unit-specific use cases.
    • B. That describes a fully centralized delivery model, not a hub-and-spoke structure where spokes do local work.
    • C. Independent assurance belongs to auditors; a Center of Excellence advises and enables, so combining both would compromise objectivity.
    • D. Network segmentation is an infrastructure and security task, not the core purpose of an AI Center of Excellence.

    Subdomain 4.1: Explain organizational governance structures that support AI.

    31.Policy says no model may reach production without a completed model card and a recorded risk sign-off, yet teams routinely skip both. Which role would implement this requirement as automated, enforceable controls in the delivery pipeline?

    1. A.AI auditor, who adds a blocking step to the deployment pipeline and holds releases until its own sign-off is entered
    2. B.Platform engineer, who sizes the clusters and assigns the namespaces where approved models eventually run
    3. C.Data scientist, who reminds teammates by email to attach the model card before opening a release request
    4. D.AI governance engineer, who turns policy into technical controls such as policy-as-code checks and approval gates
    Show answer & explanation

    Correct answer: D — AI governance engineer, who turns policy into technical controls such as policy-as-code checks and approval gates

    • A. Auditors assess controls independently; operating a gate they later evaluate would undermine their independence.
    • B. Capacity and namespace management does not verify that a model card and risk sign-off exist.
    • C. A manual reminder is not enforcement, which is why the requirement was already being skipped.
    • D. Governance engineers convert written policy into automated, enforceable checks so noncompliant releases cannot proceed.

    Subdomain 4.3: Summarize the impact of compliance on business use and development of AI.

    32.A privacy lead briefs executives on how the NIST AI RMF differs from the EU AI Act. Which TWO statements are accurate?(Select 2)

    1. A.The NIST AI RMF prohibits specific applications such as social scoring, while the EU AI Act is limited to non-binding recommendations
    2. B.The NIST AI RMF is a voluntary framework, whereas the EU AI Act is binding legislation enforced by authorities with penalties
    3. C.The NIST AI RMF can be certified by accredited auditors, whereas the EU AI Act can only be followed through self-declaration
    4. D.The NIST AI RMF is organised around the Govern, Map, Measure, and Manage functions, while the Act is organised around risk tiers
    5. E.The NIST AI RMF replaces the need for any other framework because it was adopted as an EU harmonised standard under the Act
    Show answer & explanation

    Correct answers: B, D — The NIST AI RMF is a voluntary framework, whereas the EU AI Act is binding legislation enforced by authorities with penalties; The NIST AI RMF is organised around the Govern, Map, Measure, and Manage functions, while the Act is organised around risk tiers

    • A. This reverses the two documents. Prohibited practices are listed in the Act, whereas the RMF does not ban any application.
    • B. The RMF is voluntary guidance with no legal sanctions attached. The EU AI Act is a regulation that national and EU authorities can enforce with fines.
    • C. Neither statement is right. The RMF has no certification scheme, and the Act uses conformity assessment procedures including notified bodies for some high-risk systems.
    • D. The RMF uses four core functions to structure risk management activities. The Act instead sorts systems into unacceptable, high, limited, and minimal risk with different duties for each.
    • E. The RMF is a US framework and is not an EU harmonised standard. Organisations often use it alongside other frameworks.

    Subdomain 4.3: Summarize the impact of compliance on business use and development of AI.

    33.A law firm wants to use an LLM to summarise privileged client contracts. Regulators and clients require that the content is never used to train a shared model and is not visible to other tenants. Which deployment best fits?

    1. A.Rely on a public model through an anonymous account created with a personal email address so that prompts are not tied to the firm
    2. B.Use a public model through the browser and redact only client names, leaving the clauses themselves in the prompt text
    3. C.Use a free public chatbot with chat history turned off, since the history setting guarantees that content is excluded from every training pipeline
    4. D.Run a private model, self-hosted or in a dedicated enterprise tenant, with contractual no-training terms and access limited to the firm
    Show answer & explanation

    Correct answer: D — Run a private model, self-hosted or in a dedicated enterprise tenant, with contractual no-training terms and access limited to the firm

    • A. Anonymity does not make privileged content safe to disclose. It bypasses governance and contracts, which would leave the firm without any recourse.
    • B. Contract clauses remain confidential even without names and may identify parties. Partial redaction does not change that the data leaves the firm's boundary.
    • C. A history toggle does not equal contractual protection and may still permit retention for abuse monitoring or safety review. Consumer services lack tenant isolation commitments.
    • D. A private deployment keeps prompts and outputs inside the organisation's control boundary. Contractual no-training terms and tenant isolation address the confidentiality constraints.

    Subdomain 4.2: Explain risks associated with AI.

    34.A team plans to fine-tune a support-ticket classifier on three years of tickets that contain names, email addresses, and payment details. Which approach best aligns with the privacy and security principle?

    1. A.Keep every field but add a disclaimer to the user interface warning that the classifier may memorize some customer data
    2. B.Minimize and de-identify the data before training, restrict access to the training set, and retain it only as long as needed
    3. C.Copy the tickets to a personal cloud notebook for faster experimentation, then delete the copy once training has finished
    4. D.Train on the full raw tickets so the model learns realistic content, then rely on the model to refuse to reveal personal details
    Show answer & explanation

    Correct answer: B — Minimize and de-identify the data before training, restrict access to the training set, and retain it only as long as needed

    • A. Incorrect. A disclaimer informs users but does not reduce the amount of personal data the model is exposed to or may leak.
    • B. Correct. Data minimization, de-identification, access restriction, and limited retention reduce both exposure and the chance of the model memorizing personal data.
    • C. Incorrect. Moving regulated data to an unmanaged personal environment is itself a data-handling violation, even if the copy is later deleted.
    • D. Incorrect. Models can memorize and regurgitate training data, and refusal behavior is not a dependable safeguard for personal information.

    Subdomain 4.2: Explain risks associated with AI.

    35.A paralegal submits a brief drafted by a generative model, and opposing counsel finds that several cited cases do not exist. Which risk category best describes this event, and which control reduces it?

    1. A.Shadow IT; block personal devices from reaching the firm's document management system outside of business hours
    2. B.Autonomous action; restrict the model to read-only access so that it cannot file documents on the paralegal's behalf
    3. C.Accuracy and performance; require human verification of citations and ground the model in vetted legal databases
    4. D.Intellectual property; remove all copyrighted case law from the model's training data and keep a detailed training log
    Show answer & explanation

    Correct answer: C — Accuracy and performance; require human verification of citations and ground the model in vetted legal databases

    • A. Incorrect. Device restrictions address unsanctioned access paths and do nothing about the correctness of the model's output.
    • B. Incorrect. The model never acted on its own here; a person submitted the brief, so limiting agent permissions would not have helped.
    • C. Correct. Fabricated citations are a model accuracy failure, and mandatory verification plus retrieval grounding on authoritative sources lowers the chance and impact.
    • D. Incorrect. The problem is invented content, not infringement, and removing legitimate legal sources would likely worsen factual quality.

    Want the full experience?

    These are just samples. Practice the full CompTIA SecAI+ question bank in quiz mode — free, no signup, with domain practice and exam simulation.