COMPTIA · CY0-001

CompTIA SecAI+ CY0-001 Exam Practice Questions

126 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 126 questions in this pack

Question 1

Which of the following job roles in an organizational governance structure develops a model from business use cases?

  1. Platform architect
  2. AI risk analyst
  3. Machine learning operations (MLOps) engineer
  4. Data scientist
Show answer and explanation

Correct answer: D. Data scientist

Data scientists develop predictive models from business use cases and requirements. They translate business problems into machine learning models, working directly with use case specifications to create the model architecture and approach. While platform architects design systems and MLOps engineers operationalize models, the data scientist role is specifically focused on model development from business requirements.

Why the other options are wrong

  • A. Platform architects design overall system infrastructure, not develop individual models from use cases.
  • B. AI risk analysts focus on identifying and mitigating risks, not developing models from business requirements.
  • C. MLOps engineers manage model deployment and operations, not the initial model development from use cases.

Question 2

An administrator, who works for a financial institution, is required to implement data security controls for data at rest within AI systems that involve data disclosure. Which of the following is the most suitable control?

  1. Data lineage
  2. Rate limits
  3. Encryption
  4. Masking
Show answer and explanation

Correct answer: C. Encryption

Encryption is the most suitable control for protecting data at rest, especially in financial institutions where data disclosure is a concern. Encryption renders data unreadable without the proper decryption keys, providing a fundamental security layer that prevents unauthorized access to sensitive information regardless of how the data is stored or breached.

Why the other options are wrong

  • A. Data lineage tracks data flow and origins but does not protect data from disclosure.
  • B. Rate limits control access frequency but do not protect the data itself from being read if accessed.
  • D. Masking obscures data display but does not prevent access to underlying plaintext data at rest.

Question 3

A security engineer needs to monitor an AI-based system for runtime operations. The engineer is mostly concerned about the visibility of internal activity. Which of the following is the most appropriate monitoring solution?

  1. Deploying a security information and event management (SIEM) tool
  2. Implementing a web application firewall (WAF) with header logging
  3. Relying on vendor model controls and monitoring prompt inputs
  4. Enabling stack call and debugging level traces at the function level
Show answer and explanation

Correct answer: D. Enabling stack call and debugging level traces at the function level

function level Enabling stack call and debugging level traces at the function level provides the deepest visibility into internal activity and execution flow of an AI system. This approach captures detailed function-level execution information, variable states, and control flow, which is essential for understanding internal behavior during runtime operations.

Why the other options are wrong

  • A. SIEM tools are designed for security event management across infrastructure but may not provide sufficient granularity into AI model internal operations.
  • B. WAF with header logging focuses on web layer attacks and request/response headers, not internal AI system activity.
  • C. Relying solely on vendor controls and prompt input monitoring does not provide visibility into the internal computational processes and function-level execution of the AI system.

See all 10 free questions Get the full pack, US$39

126 practice questions for CompTIA SecAI+ (CY0-001), with full explanations.

Every question comes with the correct answer, a clear explanation, and a note on why each other option is wrong. Mapped to the current CY0-001 objectives.

  • 126 questions, MCQs and PBQs, mapped to the CY0-001 objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed CY0-001 attempt costs the full US$298 voucher again. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 126 questions

What makes the SecAI+ hard

The CY0-001 only launched on 17 February 2026, so most people preparing for the SecAI+ are studying from textbooks and generic practice questions that look nothing like the real exam. Every question in this pack has been mapped to the actual objectives and verified against the current blueprint, and the bank grows every month as more questions are confirmed.

One thing to plan for: securing AI systems alone is 40% of the exam. It is by far the heaviest domain, and it is where most of the performance-based content sits.

About the exam

The CompTIA SecAI+ is the first certification purpose-built for AI security. It validates the ability to secure AI systems, defend against AI-driven threats, and apply AI governance and compliance frameworks in a real-world environment. It is aimed at cybersecurity professionals with three to four years of experience looking to specialise in AI security. Current version V1, series code CY0-001, launched 17 February 2026.

Exam domains

  • Basic AI concepts related to cybersecurity: 17%
  • Securing AI systems: 40%
  • AI-assisted security: 24%
  • AI governance, risk and compliance: 19%

Up to 60 questions including PBQs, 60 minutes, pass mark 600 out of 900, US$298 per voucher, available in English and Japanese.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the CompTIA SecAI+ CY0-001 pack?

126 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.