// COMPTIA SECAI+ · CY0-001

CompTIA SecAI+ practice test — attack, defend, and govern AI

SecAI+ launched in 2026 and prep for it is still thin. CrushCert gives you 100 adaptive practice questions written to the official CY0-001 objectives — prompt injection, the OWASP LLM Top 10, MITRE ATLAS, guardrails and AI gateways, AI in the SOC, and the EU AI Act and NIST AI RMF — with a written explanation on every answer, hands-on AI security labs, and a full timed mock exam.

Start studying free See what's on the exam

7 days free · No card required · Built to pass you on the first try

100
practice questions
60
minutes on exam
4
exam domains
$15/mo
Single exam

How CrushCert gets you exam-ready

WHAT SETS US APART

Written to the CY0-001 objectives

Questions are weighted exactly like the real exam — 17/40/24/19 across the four domains — so the mix you practice is the mix you'll face, with Securing AI systems getting the 40% it deserves.

Adaptive practice

The algorithm tracks every question you miss and serves more of those topics, so your weak areas get more reps and every session moves your score.

Realistic mock exams

Full-length, timed tests that mirror the real exam — 60 questions, 60-minute countdown, question navigator, mark-for-review, and a 67% pass line so you know you're ready before exam day.

What's on the CompTIA SecAI+ exam

SecAI+ (CY0-001) has a maximum of 60 multiple-choice and performance-based questions in 60 minutes, with a passing score of 600 on a 100–900 scale. CompTIA recommends 3–4 years in IT and 2+ years of hands-on cybersecurity experience. The four domains and weightings:

DomainWeight
Basic AI concepts related to cybersecurity17%
Securing AI systems40%
AI-assisted security24%
AI governance, risk, and compliance19%

CrushCert's question bank maps to every domain. Topic coverage includes:

Prompt injection & jailbreaksOWASP LLM Top 10MITRE ATLASData & model poisoningGuardrails & AI gatewaysAgent least privilegeRAG & vector store securityDeepfakes & AI-driven attacksAI in the SOCNIST AI RMFEU AI ActISO/IEC 42001

Train on every domain above

Adaptive practice questions and hands-on labs mapped to these exact domains. 7 days free, no card required.

Start free trial

Sample CompTIA SecAI+ practice questions

Sample — Securing AI Systems
A RAG assistant summarizes a supplier's web page for employees. Hidden white-on-white text on the page tells the model to add a link to a credential-harvesting site in every answer. Which OWASP Top 10 for LLM Applications risk is this?
A) Data and Model Poisoning
B) Prompt Injection (indirect) ✓
C) Excessive Agency
D) Misinformation

Instructions hidden in external content the model reads are indirect prompt injection. Poisoning tampers with training or fine-tuning data, excessive agency is about what the model is allowed to do, and misinformation is about false output without an attacker steering it. Every CrushCert question includes an explanation like this.

Sample — Securing AI Systems
An LLM agent that drafts customer replies also has a tool credential that can issue refunds of any amount. Which control BEST limits the damage if the agent is manipulated?
A) A longer system prompt that forbids unauthorized refunds
B) Switching to a larger, more capable model
C) Scoping the tool credential to read-only actions and requiring human approval for refunds ✓
D) Lowering the model's temperature so its actions are more predictable

Least privilege and human-in-the-loop approval are enforced outside the model, so injected text can't talk its way past them. Prompt rules can be jailbroken, and model size or temperature doesn't change what the credential is allowed to do.

Sample — Basic AI Concepts
In a retrieval-augmented generation (RAG) system, what does the vector database store?
A) Numeric embeddings of document chunks, used to find text similar to the user's question ✓
B) The model's weights, so it can be retrained on each query
C) A log of every prompt and response for auditing
D) Encrypted copies of the system prompt

Documents are split into chunks and converted to embeddings; at query time the most similar chunks are retrieved and added to the prompt. That also makes the vector store a security boundary: it needs the same access controls as the source documents.

Sample — AI-Assisted Security
A finance manager gets a call in what sounds exactly like the CFO's voice, urgently requesting a wire transfer to a new vendor. What should the manager do?
A) Approve it, because the voice matches the CFO's
B) Ask the caller a personal question only the CFO would know
C) Hang up and call the CFO back on a number from the company directory ✓
D) Ask the caller to confirm the request by email

AI voice cloning makes caller voice an unreliable identity check. Out-of-band verification through a known-good channel defeats the deepfake; a personal question can be researched, and an email confirmation could come from the same compromised or spoofed source.

Sample — AI Governance, Risk & Compliance
What are the four core functions of the NIST AI Risk Management Framework?
A) Identify, Protect, Detect, Respond
B) Govern, Map, Measure, Manage ✓
C) Plan, Do, Check, Act
D) Assess, Authorize, Monitor, Retire

The NIST AI RMF core is Govern, Map, Measure, Manage. Identify/Protect/Detect/Respond comes from the NIST Cybersecurity Framework, and Plan-Do-Check-Act is the management-system cycle used by ISO standards.

Why learners pick CrushCert

You practice the way the exam tests you. SecAI+ is scenario-heavy — "an agent was hijacked, which control BEST limits the damage?" — not definition recall. Every CrushCert question is written in that style, every explanation tells you why the other three choices are wrong, and hands-on labs drill the judgment calls — mapping attacks to the OWASP LLM Top 10, matching controls to threats, and working a prompt-injection incident ticket.

Pay for one exam or all of them. CompTIA SecAI+ alone is $15/month; the Professional plan is $24/month and covers all 16 exams — Security+, CySA+, CASP+, the CCNP exams, AWS Solutions Architect and more — so if you're stacking certs, it's all included.

You always know your readiness. A live readiness score blends your quiz accuracy, mock results, and lab performance, and points you to exactly what to study next.

A guided plan tells you what to study today. Guided Learning builds a short daily plan from your performance — a warm-up review, a lesson on your weakest topic, and flashcards, all in about 20 minutes, with spaced repetition so material comes back right before you'd forget it.

Keep learning: security & AI path

START HERE

CompTIA Security+ practice test

The security foundation SecAI+ builds on. If you don't have Security+ yet, it's the natural first step.

PAIRS WELL

CompTIA CySA+ practice test

Security operations and threat detection — the SOC skills that the AI-assisted security domain applies AI to.

STUDY PLAN

SecAI+ study plan: 2-week & 4-week schedules

A day-by-day CY0-001 plan, plus a cheat sheet matching each AI attack to the control that BEST stops it.

AI FOUNDATIONS

AWS AI Practitioner practice test

New to AI and ML concepts? The foundational AWS AI exam covers models, RAG, and prompting from the ground up.

Not sure which cert comes next? Take the two-minute Which certification should I take? quiz.

Ready to crush CompTIA SecAI+?

Adaptive questions, hands-on labs, explanations on every answer, and full mock exams — start free for 7 days, no card required.

Start studying free

CompTIA SecAI+ FAQ

How many questions are on the CompTIA SecAI+ exam?

SecAI+ (CY0-001) has a maximum of 60 questions, a mix of multiple-choice and performance-based items, with a 60-minute time limit. It launched in February 2026.

What score do you need to pass SecAI+?

600 on a 100–900 scale. CrushCert mock exams use a 67% pass line to mirror that bar.

Do I need Security+ before SecAI+?

It isn't required, but CompTIA recommends 3–4 years in IT with at least 2 years of hands-on cybersecurity, and suggests Security+, CySA+, PenTest+ or equivalent knowledge first. SecAI+ assumes you already know core security concepts and adds the AI layer on top.

How is SecAI+ different from AWS AI Practitioner?

AWS AI Practitioner is a foundational exam about AI concepts and AWS AI services. SecAI+ is vendor-neutral and security-focused: attacking and defending AI systems (OWASP LLM Top 10, MITRE ATLAS), using AI in security operations, and AI governance and regulation. CrushCert covers both.