CompTIA CY0-001: A Hands-On Study Plan
CompTIA CY0-001 is the SecAI+ certification exam. The CY0-001 exam measures four domains: Basic AI Concepts Related to Cybersecurity (17%), Securing AI Systems (40%), AI-assisted Security (24%), and AI Governance, Risk, and Compliance (19%).
The weighting should shape your preparation. Almost half the effort should go into protecting AI systems, with the rest split across AI fundamentals, defensive use of AI, and governance. A strong study plan uses one small AI application and one security-operations workflow so the concepts become practical.
Review machine learning, deep learning, generative AI, training, inference, models, embeddings, retrieval, agents, prompts, and common AI architectures. Keep the focus on how those components create assets and trust boundaries.
For each concept, write the security question it creates. Training data raises provenance and poisoning questions; inference endpoints raise access and abuse questions; agents raise tool authorization questions; embeddings and retrieval raise data exposure questions.
Draw a data-flow diagram with user, application, identity, model endpoint, retrieval source, vector store, tools, external APIs, logs, and deployment pipeline. Mark where untrusted input enters and where sensitive data can leave.
The internal STRIDE threat modeling article is useful because classic threat-model discipline still applies. Add AI-specific abuse cases without abandoning assets, trust boundaries, actors, controls, and residual risk.
Include model and provider boundaries explicitly. If the model is hosted by a third party, record what data crosses the boundary, what logs the organization can access, how authentication works, and which controls remain the provider’s responsibility.
Add a second diagram after you introduce a tool-using agent. Tool permissions create new paths from model output to business action, so the trust model changes even if the model itself is unchanged.
Test both direct and indirect prompt injection. Put hostile instructions in a user prompt and in retrieved content, then observe whether the system treats untrusted text as authoritative.
Reduce tool permissions, validate sensitive actions, separate trusted instructions from untrusted data, require human approval for high-impact operations, and log attempts. The goal is not to create an impossible “perfect prompt,” but to design limited blast radius when model behavior is manipulated.
Add data exfiltration attempts to the lab. Ask the model to reveal system instructions, hidden context, unrelated records, or credentials and observe which layer prevents disclosure. This makes confidentiality controls visible.
Then test tool parameter manipulation. Even if the model is allowed to call a tool, the application should validate that identifiers, destinations, amounts, or other sensitive parameters remain within the user’s authorization.
Review data poisoning, model tampering, malicious dependencies, insecure registries, leaked credentials, and third-party AI services. Record the provenance of models and datasets used in the lab.
The machine-learning pipeline security material is useful here. AI supply chains contain code, data, model artifacts, packages, credentials, and deployment automation, each of which can be attacked independently.
Verify artifact integrity where practical. Model files, container images, packages, and deployment code should come from approved sources and move through a controlled pipeline. A tampered dependency can compromise AI behavior before any prompt reaches the system.
Create an inventory entry for each major AI dependency with owner, version, source, privilege, update process, and retirement status. Inventory is a security control when systems change as quickly as AI stacks do.
Build a small defensive workflow where AI summarizes alerts, classifies findings, extracts indicators, drafts investigation notes, or proposes a hypothesis. Keep the original evidence available beside the generated result.
Then create deliberate mistakes in the input and see how the AI responds. Analysts should verify claims before containment or escalation. AI-assisted security is valuable when it reduces repetitive work without replacing evidence-based judgment.
Compare AI-generated triage with a manual analyst decision on the same alert set. Record where AI saves time and where it misses context. This prevents the study plan from treating automation benefits as theoretical.
Use confidence and consequence together. A low-confidence generated summary can still be useful as a draft; a high-impact containment recommendation should require stronger verification even if the model sounds certain.
Create an AI-specific incident such as unauthorized data retrieval, prompt injection, model abuse, compromised API credentials, or a suspicious model change. Build a timeline, contain the affected capability, preserve evidence, and define recovery criteria.
The incident-response lifecycle is useful because AI incidents still require preparation, detection, analysis, containment, eradication, recovery, and lessons learned. The assets and failure modes are newer; the response discipline remains familiar.
Include model rollback or tool disablement in containment options. An AI incident may require removing a model version, disabling retrieval, revoking an API key, or temporarily disabling autonomous actions rather than isolating a host.
Preserve prompts, retrieved context, model/version metadata, tool calls, identity, and timestamps where available. AI incidents need enough evidence to reproduce the behavior and distinguish user input from system or provider changes.
Create an AI use-case intake form with business owner, data categories, model/provider, users, tools or actions, external dependencies, risk level, testing evidence, human review, logging, incident owner, and retirement plan.
Use risk tiers so a harmless drafting assistant receives lighter control than an agent that can modify customer or financial systems. Governance should be proportionate enough to support experimentation without treating high-impact autonomy casually.
Define a lightweight approval path for each tier. Low-risk internal assistance may need policy and user training; high-risk agentic systems may need threat modeling, privacy review, security testing, human approval, monitoring, and an emergency shutdown procedure.
Review the tier after major changes. Adding a new tool, dataset, external model, or autonomous action can increase risk enough that the original governance decision is no longer appropriate.
The CySA+ CS0-004 exam is the broader defensive-operations path. SecAI+ specializes in security issues created by AI systems and the use of AI inside cybersecurity work.
The Security+ SY0-701 exam is a foundational security credential. Use it to close general security gaps rather than treating its objectives as part of the SecAI+ syllabus.
The older CS0-003 exam can provide legacy CySA+ context but should not control a current 2026 plan. Use adjacent certifications to strengthen security fundamentals without confusing their objectives with CY0-001.
Use your existing security experience as a shortcut, not as a substitute. Familiar concepts such as least privilege, segmentation, logging, incident response, and supply-chain security still apply, but you need to recognize how AI changes the assets, trust boundaries, and abuse paths.
If general security concepts consume most of your study time, close those gaps first. SecAI+ becomes valuable when you can spend the majority of effort on AI-specific security and governance rather than relearning foundational controls.
Run one scenario end to end: malicious input influences the AI workflow, monitoring detects suspicious behavior, an analyst investigates, the team contains the tool or data access, governance identifies the policy gap, and the system is updated and retested.
This exercise forces every SecAI+ domain to connect. Security controls, AI-assisted analysis, risk decisions, evidence, and recovery should reinforce one another instead of existing as separate study chapters.
Create an after-action report that links the technical failure to a control improvement and a governance improvement. For example, prompt injection may lead to tighter tool permissions plus a policy requiring human approval for a class of action.
This connection is central to SecAI+: cybersecurity engineering and governance are not separate chapters when the organization is deploying AI systems that can access sensitive data or take action.
Exam week: use the official domain weights.
Spend the most time on Securing AI Systems because it represents 40% of the objectives, then verify that AI-assisted security and governance are not being neglected. Use practice questions to diagnose weak concepts rather than memorize phrasing.
The SecAI+ certification helps place CY0-001 as a dedicated AI-security specialization for experienced cybersecurity professionals.
The CompTIA certification inventory can help you navigate the broader path. CY0-001 readiness should still be judged by whether you can secure and govern a real AI workflow.
Create a weighted checklist that mirrors the four objective percentages and mark each topic by confidence. Spending equal time on every concept can underprepare the largest domain.
Finish with one scenario that requires a security control, an AI-assisted analyst action, and a governance decision at the same time. Those mixed cases are the best test that your understanding is integrated.
Run one final threat-model review from memory. List the AI assets, likely threat actors, highest-impact abuse paths, preventive controls, detective controls, and recovery options. Then compare your result with the official objectives and fill only the missing areas.
This keeps the final review practical and aligned with the largest exam domain instead of turning the last days into a glossary exercise.