CY0-001 Sample Questions

CY0-001 Sample Questions & Answers

Securing AI systems with threat modeling and access controls makes up nearly half the weighting, alongside using AI tools that automate and strengthen security tasks, foundational AI types and data security, plus governance, risk and compliance for AI.

Launch the full CY0-001 simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    AI Governance, Risk, and Compliance · Summarize the impact of compliance on business use and development of AI

    A multinational corporation is adopting the NIST AI Risk Management Framework (AI RMF) to govern its deployment of generative AI tools. The governance team is currently defining the policies, processes, and procedures to map, measure, and manage AI risks. Which function of the NIST AI RMF are they primarily executing?

    Show answer & explanation

    Correct answer: A

    The GOVERN function in the NIST AI RMF is a cross-cutting function that cultivates and implements a culture of risk management. It involves establishing the policies, processes, and procedures that support the other functions (MAP, MEASURE, MANAGE).

  2. Question 2Intermediate

    Basic AI Concepts Related to Cybersecurity · Explain the importance of data security in relation to AI

    An AI engineer is preparing a dataset for a credit scoring model. To comply with privacy regulations and reduce bias, they must ensure that sensitive attributes like 'race' and 'gender' are not directly used, but they also need to ensure the model doesn't infer these attributes from proxies like 'zip code'. Which data processing technique should be applied to assess and mitigate this specific risk before training?

    Show answer & explanation

    Correct answer: B

    Fairness-aware data balancing and de-biasing techniques involve analyzing the dataset for correlations between proxy variables (like zip code) and protected attributes. This ensures the model does not learn discriminatory patterns indirectly, addressing both privacy and bias/fairness concerns.

  3. Question 3Intermediate

    Securing AI Systems · Given a set of requirements, implement security controls for AI systems

    A security operations center (SOC) is integrating a new AI-assisted tool that uses a Large Language Model (LLM) to summarize security incident logs. To prevent sensitive Personally Identifiable Information (PII) from leaking into the public model used by the vendor, which control should be implemented at the 'Gateway' layer of the architecture?

    Show answer & explanation

    Correct answer: A

    A Data Masking or Redaction Proxy placed at the gateway layer intercepts outgoing prompts before they reach the external LLM. It identifies and replaces PII (like IP addresses, usernames, emails) with generic tokens or redacted text, ensuring the public model never processes the raw sensitive data.

  4. Question 4Beginner

    Securing AI Systems · Given a scenario, implement appropriate access controls for AI systems

    When deploying an AI agent with the ability to execute code and query databases, which security principle is MOST critical to prevent 'Excessive Agency' vulnerabilities where the agent performs actions beyond the user's intent?

    Show answer & explanation

    Correct answer: B

    Least Privilege is the most critical principle for preventing Excessive Agency. The AI agent should only be granted the minimum permissions necessary to perform its specific task. If the agent is compromised or confused (hallucination), restricted permissions prevent it from deleting databases, accessing unauthorized files, or executing dangerous system commands.

  5. Question 5Intermediate

    Securing AI Systems · Given a scenario, analyze the evidence of an attack and suggest compensating controls

    An MLOps engineer is reviewing the security of a new model deployment pipeline. They discover that the model files (serialized objects) are being loaded directly from a public repository without verification. Which vulnerability is this pipeline MOST susceptible to?

    Show answer & explanation

    Correct answer: B

    Machine learning models are often stored as serialized objects (e.g., Python pickle files). Loading these files without verification allows for Insecure Deserialization, where malicious code embedded in the model file executes upon loading. This is a classic Supply Chain attack vector in AI/ML.

  6. Question 6AdvancedSelect 2

    AI Governance, Risk, and Compliance · Explain risks associated with AI

    Which TWO of the following are primary components of the 'Manage' function in the NIST AI Risk Management Framework? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    The MANAGE function involves prioritizing risk treatments and allocating resources to address identified risks.

    The core of the MANAGE function is the application of controls and mechanisms to mitigate, transfer, avoid, or accept the risks identified in the MAP and MEASURE phases.

Ready for the real thing?

The full CY0-001 simulator has every exam-style question, timed mode, and instant scoring.