EnglishDeutschFrançaisEspañolPortuguês

CompTIA SecAI+ CY0-001: what it tests and how to practice

Understand SecAI+ coverage, exam format and recommended experience, then work through an AI security exercise using an internal HR assistant.

Last updated: September 9, 2026

Prepared with AI assistance by Pass-IT. Vendor sources support exam facts; the exercises and study recommendations are ours.

CompTIA SecAI+ expands security work into AI: protecting systems and data, assessing AI-assisted decisions and assigning responsibility for risk. Choose it according to the work you want to handle, such as reviewing an internal assistant’s access to confidential information.

Coverage and exam format

CompTIA’s SecAI+ page identifies CY0-001 V1 and four domains: AI basics (17%), securing AI (40%), AI-assisted security (24%) and AI governance, risk and compliance (19%). These weights guide coverage; they do not predict exact question counts or difficulty.

The exam has a maximum of 60 questions in 60 minutes, with a scaled passing score of 600 on a 100–900 scale. This scaled score is not a percentage of correct answers. English and Japanese are available.

CompTIA recommends 3–4 years of IT experience, including at least 2 years of hands-on security experience, plus Security+, CySA+, PenTest+ or equivalent knowledge. These are recommendations, not mandatory certifications.

Design an assistant’s access controls

For an original paper exercise, sketch an internal assistant that retrieves HR documents for two departments. Your inputs are a user’s verified identity, department membership, document permissions and a request for leave-policy information. Include a restricted personnel document and a document containing malicious instructions to ignore access rules.

The expected design enforces permission and tenant filters during retrieval, before content reaches the model. A prompt alone cannot enforce access. Treat instructions found inside documents as untrusted content. Log enough to investigate decisions without recording unnecessary sensitive material.

Explain how retrieval works, how you protect the data and who owns the risk. These decisions connect AI basics, securing AI and governance. To explore AI-assisted security, add an AI recommendation to disable an account: require human approval or a defined automation policy before execution.

Test the boundary and review gaps

Check that an authorized user receives an allowed document and cannot retrieve the restricted one. If access fails, inspect identity mapping, permissions and retrieval filters. Do not solve it by widening access. Check that malicious document instructions cannot change authorization.

This exercise and original Pass-IT practice questions are not real exam questions. Find relevant practice questions and explanations, use the explanations to review your reasoning and check the exam code when choosing material.

Exam records and sources

Put what you learned into practice

Find your certification and try sample questions with explanations. See what you understand and what needs another look before choosing paid access.