Introduction
About the SecAI+ exam
()
1. The SecAI+ Exam
The SecAI+ exam
()
Careers in AI security
()
The Value of Certification
()
Study resources
()
2. Inside the SecAI+ Exam
In-person exam environment
()
At-home testing
()
SecAI+ question types
()
Passing the SecAI+ exam
()
Exam tips
()
3. Domain 1: Basic AI Concepts Related to Cybersecurity
Overview of the Basic AI Concepts Related to Cybersecurity Domain
()
4. Types of AI
Types of AI
()
Machine learning
()
Deep learning
()
Natural language processing
()
LLMs vs. SLMs
()
Generative AI
()
5. Model Training Techniques
Supervised learning
()
Unsupervised learning
()
Reinforcement learning
()
Federated learning
()
Model validation
()
Model fine-tuning
()
6. Prompt Engineering
Prompt engineering
()
Prompt roles
()
Zero-shot prompting
()
One-shot prompting
()
Multi-shot prompting
()
7. Data Processing
Data types
()
Data cleansing
()
Data verification
()
Data integrity
()
Data lineage and provenance
()
Data augmentation
()
Data balancing
()
Watermarking
()
8. Retrieval-Augmented Generation (RAG)
Retrieval-Augmented Generation (RAG)
()
Securing the knowledge store
()
Integrity of retrieved data
()
RAG privacy considerations
()
9. Security in the AI Lifecycle
The AI lifecycle
()
Business alignment in the AI lifecycle
()
Data collection
()
Data preparation
()
Model development and selection
()
Model evaluation and validation
()
Model deployment and integration
()
Monitoring and Maintenance
()
10. Human-Centric AI Design
Human-centric AI design
()
Human-in-the-loop
()
Human oversight
()
Human validation
()
11. Domain 2: Securing AI Systems
Overview of the Securing AI Systems domain
()
12. Data and Training Attacks
Data poisoning
()
Model poisoning
()
Introducing biases
()
Transfer learning attacks
()
Model skewing
()
Backdoor and trojan attacks
()
13. Prompt and Input Manipulation Attacks
Prompt injection
()
Circumventing guardrails and jailbreaking
()
Input manipulation
()
14. Model Extraction and Information Leakage Attacks
Model inversion
()
Membership Inference
()
Model Theft
()
Sensitive information disclosure
()
15. Integration and Operational Attacks
Manipulating application integrations
()
AI supply chain attacks
()
Insecure plug-in design
()
Insecure output handling
()
Output integrity attacks
()
Model denial of service
()
Excessive agency
()
Overreliance
()
AI hallucinations
()
16. AI Security Controls
Model risk assessment
()
Model Guardrails
()
Prompt templates
()
Guardrail testing and validation
()
17. AI Access Controls
Prompt firewalls
()
Limits and quotas
()
Model access controls
()
Data access controls
()
Agent access controls
()
Network and API access controls
()
18. Encryption and Data Safety
Data encryption
()
Data classification labeling
()
Data minimization
()
Data redaction
()
Data masking
()
Data anonymization
()
19. AI Monitoring and Auditing
Monitoring prompts and responses
()
Log monitoring
()
Rate and Cost Monitoring
()
Auditing for AI hallucinations
()
Auditing for accuracy
()
Auditing for Bias and Fairness
()
Auditing access and security compliance
()
20. Domain 3: AI-Assisted Security
Overview of the AI-assisted Security Ddmain
()
21. AI-Assisted Security Tools
AI in security tools
()
IDE plug-ins
()
Browser plug-ins
()
CLI plug-ins
()
Chatbots and Personal Assistants
()
MCP servers
()
22. AI Security Use Cases
Threat detection and prevention
()
Secure code development
()
Penetration testing
()
Incident response and management
()
Language-driven security operations
()
23. AI-Enabled Attacks
Deepfake content
()
Adversarial networks
()
Reconnaissance
()
Social engineering
()
Obfuscation
()
Automated data correlation
()
Automated attack generation
()
24. Automating Security Tasks
Scripting tools
()
Document synthesis and summarization
()
Incident response ticket management
()
Change management
()
AI agents
()
AI in the CI/CD pipeline
()
25. Domain 4: AI Governance, Risk, and Compliance
Overview of the AI Governance, Risk, and Compliance domain
()
26. AI Governance
Governing AI
()
Organizing for AI
()
AI policies and procedures
()
AI-Related Roles
()
27. AI Risks
Responsible AI
()
AI risks
()
Introduction of bias
()
Accidental data leakage
()
Reputational loss
()
Accuracy and performance of the model
()
Intellectual property risks
()
Autonomous systems
()
Shadow IT and shadow AI
()
Awareness training
()
28. AI Compliance
AI compliance
()
EU AI Act
()
OECD standards
()
ISO AI standards
()
NIST AI Risk Management Framework
()
Corporate AI policies
()
Third-party compliance evaluations
()
Data Sovereignty
()
What's Next?
Preparing for the exam
()