CompTIA SecAI+ practice test — attack, defend, and govern AI
SecAI+ launched in 2026 and prep for it is still thin. CrushCert gives you 100 adaptive practice questions written to the official CY0-001 objectives — prompt injection, the OWASP LLM Top 10, MITRE ATLAS, guardrails and AI gateways, AI in the SOC, and the EU AI Act and NIST AI RMF — with a written explanation on every answer, hands-on AI security labs, and a full timed mock exam.
7 days free · No card required · Built to pass you on the first try
How CrushCert gets you exam-ready
Written to the CY0-001 objectives
Questions are weighted exactly like the real exam — 17/40/24/19 across the four domains — so the mix you practice is the mix you'll face, with Securing AI systems getting the 40% it deserves.
Adaptive practice
The algorithm tracks every question you miss and serves more of those topics, so your weak areas get more reps and every session moves your score.
Realistic mock exams
Full-length, timed tests that mirror the real exam — 60 questions, 60-minute countdown, question navigator, mark-for-review, and a 67% pass line so you know you're ready before exam day.
What's on the CompTIA SecAI+ exam
SecAI+ (CY0-001) has a maximum of 60 multiple-choice and performance-based questions in 60 minutes, with a passing score of 600 on a 100–900 scale. CompTIA recommends 3–4 years in IT and 2+ years of hands-on cybersecurity experience. The four domains and weightings:
| Domain | Weight |
|---|---|
| Basic AI concepts related to cybersecurity | 17% |
| Securing AI systems | 40% |
| AI-assisted security | 24% |
| AI governance, risk, and compliance | 19% |
CrushCert's question bank maps to every domain. Topic coverage includes:
Train on every domain above
Adaptive practice questions and hands-on labs mapped to these exact domains. 7 days free, no card required.
Start free trialSample CompTIA SecAI+ practice questions
Instructions hidden in external content the model reads are indirect prompt injection. Poisoning tampers with training or fine-tuning data, excessive agency is about what the model is allowed to do, and misinformation is about false output without an attacker steering it. Every CrushCert question includes an explanation like this.
Least privilege and human-in-the-loop approval are enforced outside the model, so injected text can't talk its way past them. Prompt rules can be jailbroken, and model size or temperature doesn't change what the credential is allowed to do.
Documents are split into chunks and converted to embeddings; at query time the most similar chunks are retrieved and added to the prompt. That also makes the vector store a security boundary: it needs the same access controls as the source documents.
AI voice cloning makes caller voice an unreliable identity check. Out-of-band verification through a known-good channel defeats the deepfake; a personal question can be researched, and an email confirmation could come from the same compromised or spoofed source.
The NIST AI RMF core is Govern, Map, Measure, Manage. Identify/Protect/Detect/Respond comes from the NIST Cybersecurity Framework, and Plan-Do-Check-Act is the management-system cycle used by ISO standards.
Why learners pick CrushCert
You practice the way the exam tests you. SecAI+ is scenario-heavy — "an agent was hijacked, which control BEST limits the damage?" — not definition recall. Every CrushCert question is written in that style, every explanation tells you why the other three choices are wrong, and hands-on labs drill the judgment calls — mapping attacks to the OWASP LLM Top 10, matching controls to threats, and working a prompt-injection incident ticket.
Pay for one exam or all of them. CompTIA SecAI+ alone is $15/month; the Professional plan is $24/month and covers all 16 exams — Security+, CySA+, CASP+, the CCNP exams, AWS Solutions Architect and more — so if you're stacking certs, it's all included.
You always know your readiness. A live readiness score blends your quiz accuracy, mock results, and lab performance, and points you to exactly what to study next.
A guided plan tells you what to study today. Guided Learning builds a short daily plan from your performance — a warm-up review, a lesson on your weakest topic, and flashcards, all in about 20 minutes, with spaced repetition so material comes back right before you'd forget it.
Keep learning: security & AI path
CompTIA Security+ practice test
The security foundation SecAI+ builds on. If you don't have Security+ yet, it's the natural first step.
PAIRS WELLCompTIA CySA+ practice test
Security operations and threat detection — the SOC skills that the AI-assisted security domain applies AI to.
STUDY PLANSecAI+ study plan: 2-week & 4-week schedules
A day-by-day CY0-001 plan, plus a cheat sheet matching each AI attack to the control that BEST stops it.
AI FOUNDATIONSAWS AI Practitioner practice test
New to AI and ML concepts? The foundational AWS AI exam covers models, RAG, and prompting from the ground up.
Not sure which cert comes next? Take the two-minute Which certification should I take? quiz.
Ready to crush CompTIA SecAI+?
Adaptive questions, hands-on labs, explanations on every answer, and full mock exams — start free for 7 days, no card required.
Start studying freeCompTIA SecAI+ FAQ
How many questions are on the CompTIA SecAI+ exam?
SecAI+ (CY0-001) has a maximum of 60 questions, a mix of multiple-choice and performance-based items, with a 60-minute time limit. It launched in February 2026.
What score do you need to pass SecAI+?
600 on a 100–900 scale. CrushCert mock exams use a 67% pass line to mirror that bar.
Do I need Security+ before SecAI+?
It isn't required, but CompTIA recommends 3–4 years in IT with at least 2 years of hands-on cybersecurity, and suggests Security+, CySA+, PenTest+ or equivalent knowledge first. SecAI+ assumes you already know core security concepts and adds the AI layer on top.
How is SecAI+ different from AWS AI Practitioner?
AWS AI Practitioner is a foundational exam about AI concepts and AWS AI services. SecAI+ is vendor-neutral and security-focused: attacking and defending AI systems (OWASP LLM Top 10, MITRE ATLAS), using AI in security operations, and AI governance and regulation. CrushCert covers both.