What Changes in Security+ SY0-801: AI and LLM Objectives Explained

SY0-801's draft adds 3 distinct AI objectives, covering LLMs, AI as a weapon, and AI as a defensive tool. Full breakdown of exactly what's expected to be tested and why.
SY0-801 AI LLM objectives

SY0-701 mentions AI only in passing. SY0-801’s draft objectives add not one but 3 distinct AI-related objectives, spread across 2 different domains, covering AI as something you need to secure, AI as a weapon attackers now use against you, and AI as a defensive tool you’ll increasingly rely on yourself. This is the single biggest content shift in the entire draft blueprint, and it deserves a real, specific breakdown rather than a vague “AI content is coming” summary.

Important caveat before anything else: everything below is based on draft version 1.2 objectives, not a finalized, officially published blueprint. Objective numbers, exact wording, and scope can still shift before SY0-801 actually launches. Treat this as the most detailed picture currently available, not a locked syllabus.

The 3 New AI Objectives at a Glance

ObjectiveDomainWhat It Covers
2.4Domain 2Large Language Models specifically, how they work conceptually, and the security implications of deploying them
2.6Domain 2AI as a threat surface and as a weapon, attacks against AI systems and attacks that use AI
4.6Domain 4AI as a defensive capability, agentic systems, chatbots, predictive analysis, AI-augmented baselines

Key point: Objective 2.6 specifically has no SY0-701 ancestor of any kind, it’s an entirely new addition to the blueprint, not an expansion of something that existed before. Objective 2.4 is similarly new in substance, even though SY0-701 touched AI briefly elsewhere, this draft gives it a fully dedicated objective for the first time.

Objective 2.4: Understanding Large Language Models

This objective assumes you need to recognize the security implications of LLMs being deployed inside your organization, not that you need to build or fine-tune one yourself. Candidates should expect coverage of how LLMs function at a conceptual level, enough to reason about where risk enters the system, along with 2 specific, practical concerns: prompt injection as a distinct attack vector, and data leakage through model interactions, where sensitive information entered into a prompt or retrieved by the model ends up somewhere it shouldn’t.

On the defensive side, expect coverage of basic, practical mitigations: input validation before a prompt reaches the model, and output filtering before a model’s response reaches a user or a downstream system. These are the same defense-in-depth principles Security+ already teaches for traditional injection attacks, applied to a genuinely new context.

Real-world grounding: prompt injection isn’t a theoretical exam concept, it’s an actively documented, real attack category. Security researchers distinguish between direct prompt injection, where an attacker manipulates the system prompt directly, sometimes called jailbreaking, and indirect prompt injection, where malicious instructions are hidden inside external content, an email, a document, a web page, that the LLM retrieves and processes as part of its normal operation. Indirect injection is considered more dangerous specifically because the victim organization may never see the injected content directly, and it can require zero user interaction to succeed. Expect SY0-801 to test your ability to recognize both categories and identify the correct control for each.

Objective 2.6: AI as a Threat Surface and as a Weapon

This is the broadest of the 3 new objectives, and based on the draft, it splits cleanly into 2 halves.

AI as something that gets attacked. The draft objective list here is genuinely extensive: model manipulation, data poisoning, prompt injection, jailbreaking, evasion techniques, hallucinations, bias, explainability problems, data loss, privacy violations, ethical considerations, session hijacking, and code execution. That’s a wide net, and it signals CompTIA treats AI systems as a full asset class requiring the same breadth of security thinking as networks or endpoints, not a narrow bolt-on topic.

AI as something attackers now use against you. This half of the objective is framed practically: AI-generated phishing content that’s harder to spot than older templated scams, deepfake-enabled social engineering, automated vulnerability discovery at a scale and speed manual research can’t match, and AI-assisted malware development. The underlying message CompTIA appears to be building toward is direct: security analysts increasingly face attackers using the same categories of tools defenders use, often without the ethical or safety constraints defenders operate under.

Key point: Notice that “deepfake” and “quishing,” QR-code-based phishing, are reportedly named explicitly as new terms in the broader V8 draft, alongside this objective. If you’re studying, treat these as named, testable terms now, not generic buzzwords, since CompTIA naming something explicitly in an objective is a strong signal it’s fair game for a direct question.

Objective 4.6: AI as a Defensive Capability

This objective flips the lens entirely, and it’s easy to miss if you’re only focused on AI-as-threat coverage. It sits inside the automation and orchestration content in Domain 4, and it covers AI used defensively: agentic systems that can take autonomous action within defined guardrails, chatbots supporting security operations workflows, predictive analysis for identifying likely threats before they fully materialize, and AI-augmented baselines for detecting deviation from normal system behavior more effectively than static, rule-based baselines alone.

Why this matters for your career, not just the exam: this objective reflects where security operations work is actually heading. Analysts increasingly use AI-assisted tools for triage, correlation, and initial investigation, and understanding how these tools function, including their limitations, is becoming a genuine job skill, not just exam trivia.

What’s Changing Around the AI Content

The AI additions don’t exist in isolation, they connect to other real structural changes reported in the same draft. Old Objective 2.5, mitigation techniques, is reportedly gone as a standalone objective, with its content redistributed into a new Objective 4.1 instead, which is also why the domain title itself is expected to drop the word “Mitigations.” Zero Trust is reported to become an explicit, named architecture block under Objective 3.2, with user authentication, device health and inventory, and application access control organized underneath it directly. Security Service Edge, SSE, reportedly appears as new content, while SD-WAN and SASE, both explicitly named in SY0-701, reportedly do not appear in the V8 draft at all, a genuine omission worth knowing if you’ve already studied those specific terms. Identity management is reported to move into Domain 3, adding group managed service accounts, gMSA, as a new named acronym, along with privilege creep as a named concept.

None of this is about AI specifically, but it’s useful context: SY0-801 isn’t just “SY0-701 plus an AI chapter,” it’s a genuine structural revision happening at the same time as the AI additions, consistent with the roughly 40 percent objective-level change instructor analysis found during the SY0-601 to SY0-701 transition. For the complete decision framework on whether this magnitude of change means you should wait for SY0-801 or take SY0-701 now, see our SY0-701 vs SY0-801 guide.

What You Don’t Need to Worry About

Based on everything reported so far, SY0-801’s AI content stays conceptual and security-focused, not technical AI engineering. You’re not expected to build, train, or fine-tune a model, write machine learning code, or understand the mathematics behind how LLMs generate text. The framing throughout is consistently practical: recognize the risk, identify the right control, understand the attacker’s likely approach. That’s consistent with Security+’s existing philosophy across every other domain, applied to a new subject matter, not a fundamental shift in what kind of exam this is.

How to Start Preparing for This Content Today

Since SY0-801 hasn’t launched and no finalized study materials exist yet, the most productive thing you can do right now is build genuine conceptual familiarity with the real-world security concepts these objectives are drawing from, prompt injection, jailbreaking, data poisoning, and AI-generated social engineering are all actively documented in current security research and industry reporting, independent of this exam. Building that baseline understanding now means you’ll be reinforcing exam-specific study later rather than learning these concepts for the first time once SY0-801 materials finally catch up.

If your timeline means you’re taking SY0-701 first regardless, that’s not wasted effort either. The underlying security judgment SY0-701 builds, recognizing attack patterns, matching controls to risks, thinking in terms of defense in depth, transfers directly onto this new AI-specific content. Our SY0-701 exam objectives and domains breakdown and SY0-701 preparation guide build exactly that foundation.

For the current, complete status of SY0-801 as an exam, including launch timing and what’s officially confirmed versus still reported, see our SY0-801 release date tracker. For how this fits into the full history of Security+ versions, see our SY0-601 vs SY0-701 vs SY0-801 timeline, and for what the actual exam format and cost are expected to look like once finalized, see our SY0-801 cost and format preview.

Decision Checklist

  • Treat everything here as draft-stage information. Objective numbers and exact scope can still change before CompTIA finalizes the blueprint.
  • Don’t wait for official SY0-801 study materials to start building AI security literacy. Prompt injection, jailbreaking, and AI-enabled social engineering are real, current security topics you can study independent of any specific exam version.
  • If you see “deepfake” or “quishing” mentioned as specific named terms in draft materials, treat them as likely testable vocabulary, not generic background context.
  • Don’t assume this content requires technical AI or machine learning background. Every indication points to a security-judgment framing consistent with the rest of Security+, not a technical AI engineering test.
  • Remember this is 3 separate objectives, not one. Study AI-as-something-to-secure (2.4), AI-as-a-weapon-and-target (2.6), and AI-as-a-defensive-tool (4.6) as 3 distinct angles on the same underlying subject, since conflating them risks missing real exam content.

FAQS

How many new AI-related objectives does SY0-801 add? 

Based on draft version 1.2, 3: Objective 2.4 covering Large Language Models specifically, Objective 2.6 covering AI as a threat surface and as an attacker’s weapon, and Objective 4.6 covering AI as a defensive capability within automation and orchestration.

Do I need to know how to build or train an AI model for SY0-801? 

No. Every indication from the draft objectives points to a conceptual, security-judgment framing, recognizing risks and applying the right controls, not technical AI engineering or machine learning skill.

What is prompt injection, and why does it matter for this exam? 

Prompt injection is an attack where crafted input manipulates an AI model into ignoring its original instructions and following unauthorized commands instead. It’s a real, actively documented attack category, and it appears to be one of the most heavily emphasized concepts across multiple new SY0-801 objectives.

What’s the difference between direct and indirect prompt injection? 

Direct prompt injection, often called jailbreaking, involves manipulating a system prompt directly. Indirect prompt injection hides malicious instructions inside external content the AI system retrieves and processes, and it’s considered more dangerous since a victim may never see the injected content directly.

Are “deepfake” and “quishing” actually going to be tested? 

Both terms reportedly appear explicitly named in the broader V8 draft objectives, which is a strong signal they’re intended to be directly testable vocabulary, not just background context.

Is SY0-801’s AI content only about defending against AI, or also about using AI defensively? 

Both. Objectives 2.4 and 2.6 focus on securing and defending against AI-related risk, while Objective 4.6 specifically covers using AI as a defensive tool, agentic systems, chatbots, predictive analysis, and AI-augmented baselines.

Should I wait for SY0-801 specifically because of this AI content? 

Only if your role or interests specifically require this content now, or your study timeline naturally lands after SY0-801 launches anyway. See our full SY0-701 vs SY0-801 decision guide for the complete framework.

Leave a Replay

Table of Contents

Have You Tried Our Exam Dumps?

Cert Empire is the market leader in providing highly accurate valid exam dumps for certification exams. If you are an aspirant and want to pass your certification exam on the first attempt, CertEmpire is you way to go. 

Scroll to Top