CompTIA SecAI+ Practice Questions: 4.0 AI Governance, Risk, and Compliance

19 free, exam-style CompTIA SecAI+ (CY0-001) practice questions covering 4.0 AI Governance, Risk, and Compliance. Each question shows the correct answer and a clear explanation. Ready for the real thing? Take the full timed quiz below.

🚀 Take the full CompTIA SecAI+ quiz 📘 CompTIA SecAI+ study guide

Q1. Which of the following is a risk associated with 'Shadow AI'?

Explanation: Shadow AI refers to the use of AI tools and models by employees without organizational approval or oversight, leading to data leakage and compliance risks. Learn more.

Q2. What is the primary function of an 'AI Center of Excellence' (CoE) within an organization?

Explanation: An AI CoE is a centralized governance structure responsible for setting strategy, policies, standards, and best practices for AI adoption across the organization. Learn more.

Q3. Which emerging compliance framework categorizes AI systems based on risk levels (e.g., Unacceptable, High, Limited, Minimal)?

Explanation: The EU AI Act uses a risk-based approach, categorizing AI systems into different risk levels with varying compliance requirements. Learn more.

Q4. A security analyst observes that an AI model is consistently recommending higher loan interest rates for a specific demographic group despite equal financial qualifications. This is an example of:

Explanation: AI Bias occurs when a model produces systematically prejudiced results due to erroneous assumptions or biased training data. Learn more.

Q5. Which of the following is a key component of the NIST AI Risk Management Framework (AI RMF)?

Explanation: The NIST AI RMF Core consists of four functions: Govern, Map, Measure, and Manage. Learn more.

Q6. What is the primary risk of 'Data Leakage' when using public Large Language Models (LLMs)?

Explanation: Many public LLMs (e.g., standard ChatGPT) may use user inputs for training. Sending proprietary code or PII constitutes a data leakage risk. Learn more.

Q7. Which role is primarily responsible for ensuring that AI models are developed, deployed, and maintained efficiently and reliably (DevOps for AI)?

Explanation: MLOps (Machine Learning Operations) Engineers focus on the operationalization of ML models, including CI/CD, monitoring, and scalability. Learn more.

Q8. What is the concept of 'Explainability' (XAI) in AI governance?

Explanation: Explainability ensures that the internal decision-making process of an AI system can be understood by humans, which is crucial for trust and compliance. Learn more.

Q9. In the context of GRC, what does 'Data Sovereignty' imply for AI model deployment?

Explanation: Data sovereignty laws (like GDPR requirements) mandate that data collected from citizens must be subject to the laws of that nation, often requiring local storage/processing. Learn more.

Q10. Which governance artifact documents intended use, limitations, training data, and evaluation results for a model?

Explanation: Model cards communicate model purpose, performance, limitations, and responsible use considerations. Learn more.

Q11. Which practice helps investigate AI decisions that affect security operations?

Explanation: Audit logs support traceability, incident review, and governance for AI-assisted workflows. Learn more.

Q12. Which concept means an AI system should provide understandable reasons or evidence for important outputs?

Explanation: Explainability supports trust, review, compliance, and accountability for AI-assisted decisions. Learn more.

Q13. Which process should approve high-impact AI use cases before deployment?

Explanation: Governance review evaluates legal, security, privacy, fairness, and operational risks before deployment. Learn more.

Q14. Which AI evaluation checks whether protected groups receive unfairly different outcomes?

Explanation: Fairness testing evaluates whether model outcomes differ in inappropriate ways across groups. Learn more.

Q15. Which protection reduces exposure of personal data before model training begins?

Explanation: Reducing or anonymizing sensitive data lowers privacy risk in model development. Learn more.

Q16. Which logging practice helps reproduce an AI security incident?

Explanation: Detailed but appropriately protected audit logs support incident reconstruction and governance. Learn more.

Q17. Which process documents who owns an AI system and who approves major changes?

Explanation: Governance documentation assigns accountability, approval authority, and operating expectations. Learn more.

Q18. Which model documentation should list known limitations and inappropriate uses?

Explanation: Model cards should communicate limitations, intended uses, and unsuitable use cases. Learn more.

Q19. Which security concern applies when sending prompts to a third-party AI service?

Explanation: Prompts can contain confidential data, so third-party processing and retention must be evaluated. Learn more.

More CompTIA SecAI+ practice topics