CompTIA SecAI+ Practice Questions: 3.0 AI-assisted Security

12 free, exam-style CompTIA SecAI+ (CY0-001) practice questions covering 3.0 AI-assisted Security, each with the correct answer and an explanation. Start a timed exam below, or scroll on to read through the questions.

🧠

Mini Exam

15 Questions · 30 minutes

Start Quiz 🚀
🏆

Mock SecAI+ Exam

50 Questions · 100 minutes

Start Quiz 🚀
📅

Daily Quiz

10 Questions · 20 minutes

Start Quiz 🚀
🎯

Standard Practice

25 Questions · 50 minutes

Start Quiz 🚀

3.0 AI-assisted Security practice questions

Answers and explanations are shown. Take the timed exam above to test yourself first.

Q1. An organization is using AI to automate code scanning in their CI/CD pipeline. Which AI capability is primarily being leveraged here?

  • A.Generative Adversarial Networks (GANs)
  • B.Static Application Security Testing (SAST) analysis✓ Correct
  • C.Deepfake generation
  • D.Reinforcement learning
Explanation: AI-enhanced SAST tools scan source code to identify vulnerabilities, coding errors, and compliance issues during the CI/CD process. Learn more.

Q2. In the context of AI-assisted security, how can Deepfakes enhance social engineering attacks?

  • A.By encrypting the victim's hard drive faster
  • B.By creating realistic audio or video impersonations of executives to authorize fraud✓ Correct
  • C.By brute-forcing passwords using GPU acceleration
  • D.By identifying vulnerabilities in firewall configurations
Explanation: Deepfakes use Generative AI to create hyper-realistic audio or video impersonations, significantly increasing the success rate of BEC (Business Email Compromise) and vishing attacks. Learn more.

Q3. Which of the following is an example of an AI-enabled defensive tool?

  • A.WormGPT
  • B.FraudGPT
  • C.SOAR with automated playbook execution✓ Correct
  • D.Polymorphic malware generator
Explanation: Security Orchestration, Automation, and Response (SOAR) platforms often use AI to automate incident response playbooks and triage alerts. Learn more.

Q4. When using AI for 'Automated Attack Generation', what is a primary advantage for the attacker?

  • A.Slower attack speed
  • B.Higher cost of operation
  • C.Ability to create polymorphic malware that changes signatures to evade detection✓ Correct
  • D.Requirement for more human intervention
Explanation: AI allows attackers to generate polymorphic malware that constantly changes its code structure (signature) while maintaining functionality, bypassing traditional AV. Learn more.

Q5. A company wants to ensure their AI coding assistant does not suggest insecure libraries. They configure the tool to cross-reference suggestions against a known vulnerability database (like CVE). This is an example of:

  • A.Software Composition Analysis (SCA)✓ Correct
  • B.Generative Adversarial Network
  • C.Image classification
  • D.Reinforcement Learning
Explanation: SCA tools identify open-source components and libraries in code and check them against vulnerability databases (CVEs) to manage risk. Learn more.

Q6. A security team uses an AI tool to automatically categorize alerts as 'Critical', 'High', or 'False Positive' to reduce alert fatigue. This is an example of:

  • A.AI-assisted Incident Response / Triage✓ Correct
  • B.Data Poisoning
  • C.Model Inversion
  • D.Deepfake creation
Explanation: AI is widely used in SOCs (Security Operations Centers) to triage high volumes of alerts, allowing analysts to focus on genuine threats. Learn more.

Q7. What is the primary function of the 'Model Context Protocol' (MCP)?

  • A.To encrypt data in transit
  • B.To standardize how AI models interface with external data and tools✓ Correct
  • C.To perform DDoS attacks
  • D.To manage user passwords
Explanation: The Model Context Protocol (MCP) is an open standard that enables developers to build secure, two-way connections between AI systems and data sources. Learn more.

Q8. A SOC uses an AI model to summarize long incident timelines. What is the main security analyst responsibility?

  • A.Verify the summary against source evidence✓ Correct
  • B.Trust the output without review
  • C.Delete the original logs
  • D.Disable case notes
Explanation: AI-generated summaries can be incomplete or inaccurate, so analysts must validate them against evidence. Learn more.

Q9. Which risk occurs when an AI coding assistant suggests vulnerable code patterns?

  • A.Insecure code generation✓ Correct
  • B.Wireless roaming
  • C.Printer spooling
  • D.Cable crosstalk
Explanation: AI coding tools can produce insecure examples, so generated code still needs secure review and testing. Learn more.

Q10. Which AI-assisted SOC task can help reduce alert fatigue by grouping related alerts?

  • A.Alert clustering✓ Correct
  • B.Disk encryption
  • C.Cable testing
  • D.Printer pooling
Explanation: AI can group related alerts into incidents or clusters to reduce duplicate triage effort. Learn more.

Q11. Which risk is created when AI-generated detections are deployed without analyst review?

  • A.False positives or missed detections at scale✓ Correct
  • B.Improved keyboard layout
  • C.Guaranteed compliance
  • D.Lower audit requirements
Explanation: Generated detection logic can be wrong or incomplete and should be tested before production use. Learn more.

Q12. Which cybersecurity use case uses AI to identify emails with malicious intent?

  • A.Phishing detection✓ Correct
  • B.Disk partitioning
  • C.Printer spooling
  • D.VLAN tagging
Explanation: AI models can classify emails using content, sender, links, and behavioral indicators. Learn more.

More CompTIA SecAI+ practice topics

Keep studying CompTIA SecAI+

Full CompTIA SecAI+ practice exam · CompTIA SecAI+ study guide · All CompTIA practice questions

Last updated