CY0-001 exam format: questions, passing score, time and cost
CY0-001 is a short exam with an unusual amount packed into it. Sixty minutes, up to sixty questions, and a mix of multiple choice and performance-based items. Here are the published facts.
| Exam code | CY0-001 |
| Certification | CompTIA SecAI+ |
| Version | V1 |
| Duration | 60 minutes |
| Number of questions | Maximum of 60 |
| Question types | Multiple choice and performance-based |
| Passing score | 600 on a scale of 100–900 |
| Languages | English and Japanese |
| Launched | February 17, 2026 |
| Estimated retirement | Around three years after launch |
| Price | Not published on the certification page; check at booking |
One minute per question
That ratio is the defining feature of this exam. Sixty questions in sixty minutes leaves no room for extended deliberation, and performance-based items eat more than their share of the clock.
The practical consequence: do not let a single performance-based question consume ten minutes. Answer what you can, mark it, and come back. Candidates who fail this exam on time rather than on knowledge almost always did so by sinking early minutes into one simulation.
Performance-based questions
CompTIA’s performance-based items ask you to do something rather than pick something — matching, ordering, classifying, or completing a configuration in a simulated interface. On a SecAI+ paper they typically involve things like sorting threats into categories, mapping controls to a pipeline stage, or ordering the steps of an incident response.
Two habits help:
- Read the task statement fully before touching anything. These items often have two parts and people answer only the first.
- Partial credit generally exists. An incomplete answer beats an empty one, so never leave a simulation blank because you could not finish it.
The scale is 100–900, not 0–100
600 out of 900 is the pass mark, which is roughly 67% of the scale — but the scale does not start at zero, so it does not translate to “67% of questions correct”. CompTIA scales scores, and questions carry different weights. Aim well clear of the line rather than calculating how many you can afford to miss.
Domain weighting drives everything
| Domain | Weight | Rough questions |
|---|---|---|
| Basic AI concepts related to cybersecurity | 17% | ~10 |
| Securing AI systems | 40% | ~24 |
| AI-assisted security | 24% | ~14 |
| AI governance, risk, and compliance | 19% | ~11 |
The question counts are approximate — CompTIA publishes percentages, not counts, and the exam holds a maximum of sixty items. But the shape is clear: roughly two of every five questions come from one domain.
Recommended experience
CompTIA recommends 3–4 years in IT with 2+ years of hands-on cybersecurity work, and prior knowledge at the level of Security+, CySA+ or PenTest+. None of this is enforced — there is no gate at booking — but the questions are written for someone who already thinks in terms of controls, threats and risk.
Booking
SecAI+ is delivered through CompTIA’s usual channels: a Pearson VUE test centre or online proctored at home. If you test online, run the system check in advance on the machine and network you will actually use.
What the short format means for revision
A sixty-minute exam cannot go deep on any single topic, which changes how you should revise. Breadth beats depth here. You are far more likely to meet one question on each of twenty concepts than five questions on one. That makes flashcard-style recall of terminology unusually valuable, and makes deep-diving a single framework a poor use of the last week.
It also means you cannot afford blind spots. On a ninety-question exam you can drop a whole subtopic and still pass; on sixty questions with a 600 threshold, two unfamiliar areas can be decisive.
Retirement
CompTIA gives an estimated retirement of around three years after launch, which places it near early 2029. That is an estimate rather than a commitment, but it means a pass now carries a useful shelf life.