Home / Blog / CompTIA SecAI+ Study Plan
// COMPTIA SECAI+ (CY0-001) · STUDY PLAN

CompTIA SecAI+ study plan: 2-week and 4-week schedules

CrushCert · Published October 2026 · ~8 min read

Here's a concrete, day-by-day plan for CompTIA SecAI+ (CY0-001): a 4-week track if you know security but AI is new to you, and a 2-week track if you already work in security and use LLM tools day to day. Follow either one and finish consistently scoring 80%+ on practice exams before test day.

SecAI+ is not an AI theory exam. It assumes you already think like a security professional and asks you to apply that to AI: how a prompt injection actually reaches a model, why a system prompt is not a security boundary, which control stops an over-privileged agent, and which framework a regulator expects. This plan is built around those judgment calls.

The exam you're planning for

WhatDetail
Exam codeCY0-001
QuestionsUp to 60 (multiple choice + performance-based)
Time60 minutes
Pass score600 / 900
Recommended experience3–4 yrs IT, 2+ yrs security
DomainWeight
Basic AI concepts related to cybersecurity17%
Securing AI systems40%
AI-assisted security24%
AI governance, risk, and compliance19%

Securing AI systems alone is 40% of the exam, so both plans give it the most days. The time limit is tight too: up to 60 questions in 60 minutes, including performance-based items. Pacing practice is part of the plan, not an afterthought.

Pick your track

YouTrack
Security background, new to AI and LLMs4 weeks · ~1 hr/day
Security pro who already uses AI tools or builds with LLMs2 weeks · ~1.5–2 hrs/day
No security background yetStart with Security+ first

The daily hour (both tracks)

Every study day follows the same shape:

The one rule that matters: practice questions start on day 1. Most SecAI+ questions are scenarios ("an agent was hijacked — which control BEST limits the damage?"), and the wrong answers are usually controls that would help a little. You only learn to spot the BEST one by doing a lot of them.

The 4-week plan (new-to-AI track)

Week 1 — Basic AI concepts for security (17%)

Week 2 — Securing AI systems, part 1: the attacks (40%)

Week 3 — Securing AI systems, part 2: the controls

Week 4 — AI-assisted security, governance, and practice exams

Cheat sheet: attack → the control that BEST stops it

A big share of SecAI+ questions ask for the best control. The winning answer is usually the one enforced outside the model, because anything the model is told can be talked around:

The scenario says…Pick
Hidden instructions in an email or web page hijack the assistantTreat content as untrusted + limit tools
An agent did something harmful with its toolsLeast privilege + human approval
Users reach documents they shouldn't via the RAG botPermission-aware retrieval
Model output runs as code, SQL or HTML downstreamValidate/encode output, least-privilege execution
Secrets leaked from the system promptRemove secrets from the prompt
Bill spike or someone cloning the model with mass queriesRate limits, quotas, spend alerts
PII showing up in prompts or logsDetect and mask before logging
Untrusted model file from a public hubScan it, signed artifacts, safe formats

Watch for the classic trap: "add a stronger instruction to the system prompt." It's almost never the best answer, because a prompt rule is exactly what an injection overrides.

Practice it: CrushCert's Match the Control to the AI Threat and Name That OWASP LLM Risk hands-on labs drill exactly these calls, and the Email Agent Sent Data to an Outsider troubleshooting ticket walks you through a real prompt-injection incident from clue to fix.

The 2-week plan (experienced track)

Same structure, compressed. Take each domain's quiz first and only study what you miss.

The final 48 hours (both tracks)

Run this plan on CrushCert

Adaptive SecAI+ practice questions with an explanation on every answer for the daily reps, hands-on labs for the attack-and-control calls, full timed mock exams for week 4, and a readiness score that tells you when to book. 7-day free trial, no card required.

Start the SecAI+ plan →

Before and after SecAI+

If you don't have a security foundation yet, start with Security+ — SecAI+ builds directly on it. If AI concepts are the gap, the foundational AWS AI Practitioner covers models, RAG and prompting from the ground up. After SecAI+, CySA+ deepens the SOC side. Not sure which direction fits? Take the two-minute which certification should I take quiz.

Frequently asked questions

Can I pass CompTIA SecAI+ in 2 weeks?

Yes, if you already hold Security+ or work in security and have used LLM tools or AI features at work, and can study about 1.5 to 2 hours a day. If AI concepts are new to you, take the 4-week track.

Do I need Security+ before SecAI+?

It is not required, but CompTIA recommends 3 to 4 years in IT with at least 2 years of hands-on cybersecurity, and suggests Security+, CySA+, PenTest+ or equivalent knowledge first. The exam assumes you already know core security controls and adds the AI layer on top.

Do I need to code to pass SecAI+?

No. You need to understand how AI systems work and how they are attacked and defended, not write code. You should be able to read a prompt, a tool-permission config or a log snippet and spot what is wrong.

What practice-exam score means I'm ready for SecAI+?

Aim for 80% or higher on two full timed practice exams in a row. The real exam passes at 600 on a 100 to 900 scale (roughly 67%), so an 80%+ average leaves a comfortable margin.