- The One-Page Snapshot
- Format, Scoring and Timing Facts
- Domain Weights at a Glance
- Domain 2: Resist Social-Engineering Attacks (28%)
- Domain 4: Use the Internet Securely (28%)
- Domain 3: Secure Devices (24%)
- Domain 1: Use Technology Responsibly (20%)
- Cost, Access and Eligibility Facts
- The Version Trap: CBS-510 vs. CBS-410
- A Domain-Ordered Review Plan
- Cheat Sheet FAQ
- CyberSAFE CBS-510 has 25 multiple-choice/multiple-response questions; you need 80% (20 of 25) to pass.
- Social-engineering resistance and secure Internet use each carry 28%, together over half the blueprint.
- Retakes are unlimited, and there are no formal registration prerequisites or application fees.
- The published USD 15.17 price is a Student Digital Course Bundle, not an exam-only fee.
The One-Page Snapshot
This cheat sheet condenses everything a candidate should have memorized before sitting CyberSAFE: Securing Assets for End Users, the end-user cyber awareness credential issued by CertNexus. The current assessment is CBS-510, launched in October 2025 and marketed as CyberSAFE: Cyber Safety in the Age of AI. It is aimed at everyday workers, not IT specialists, which explains both its approachable format and its heavy emphasis on judgment calls: spotting a suspicious message, deciding what not to paste into an AI tool, and knowing when and how to report an incident.
If you are brand new to the credential, start with What Is CyberSAFE? for background, then come back here for the quick-reference version. For a deeper preparation roadmap, the CyberSAFE Study Guide 2026 expands on everything below.
| Fact | CyberSAFE CBS-510 |
|---|---|
| Issuer | CertNexus |
| Credential type | End-user credential with a digital badge |
| Assessment code | CBS-510 (launched October 2025) |
| Questions | 25, multiple-choice and multiple-response |
| Passing score | 80% (20 of 25) |
| Retakes | Unlimited |
| Typical completion time | Roughly 20-45 minutes (estimates vary by page) |
| Delivery | Online, through CHOICE or the issuer's e-learning offering |
| Prerequisites | None formal |
Format, Scoring and Timing Facts
Question style
The assessment consists of 25 questions mixing multiple-choice (one correct answer) and multiple-response (select all that apply) items. The multiple-response items are where careless candidates lose points, because partial knowledge of a list is not enough. When a question asks you to choose more than one answer, treat each option as its own true/false judgment.
The 80% bar
Passing requires 20 of 25 correct, which leaves room for only five misses. That is a stricter threshold than many introductory awareness assessments, and it means you cannot afford to skip an entire domain and hope to compensate elsewhere. With domains weighted at 28%, 28%, 24% and 20%, a weak area can sink an attempt quickly. The CyberSAFE Passing Score guide breaks the arithmetic down further.
How long does it take?
Published guidance gives completion estimates of 20-45 minutes in the blueprint and current-page FAQ, and a 20-40-minute average in the assessment table. These are completion estimates, not a verified fixed exam timer, so do not plan around a hard cutoff, and do not assume the number is a rule. Separately, the half-day training associated with the course is distinct from assessment completion time; do not add the two together when planning your day.
Domain Weights at a Glance
The four domains below come from the official CBS-510 Exam Blueprint, version 1.0, issued October 10, 2025. They are weighted assessment objectives, so the percentages tell you where the questions come from.
| Domain | Weight | Approx. share of 25 questions |
|---|---|---|
| Domain 1: Use Technology Responsibly | 20% | about 5 |
| Domain 2: Resist Social-Engineering Attacks | 28% | about 7 |
| Domain 3: Secure Devices | 24% | about 6 |
| Domain 4: Use the Internet Securely | 28% | about 7 |
The question-count column is simple arithmetic on the stated weights against a 25-question form, offered as a planning aid rather than a guaranteed distribution. The complete objective-by-objective breakdown lives in the CyberSAFE Exam Domains Guide.
Domain 2: Resist Social-Engineering Attacks (28%)
Tied for the heaviest domain, this is where the credential's modern, AI-era focus is most visible. You are expected to recognize manipulation across every channel an attacker might use.
Attack types to recognize on sight
Know the delivery channel and the tell-tale signs of each.
- Phishing: deceptive email designed to steal credentials or push malware.
- Smishing: the same tactic delivered by text message.
- Vishing: voice-call manipulation, often posing as IT, a bank or an executive.
- Deepfakes: synthetic video or imagery used to impersonate a trusted person.
- Voice cloning: AI-generated audio that mimics a real colleague or relative.
The reflexes the exam rewards
- Verify through a second, known channel. If a "manager" requests an urgent transfer by voice or video, confirm using a number or contact you already trust, not one supplied in the message.
- Slow down when urgency is manufactured. Pressure, fear and secrecy are classic manipulation signals.
- Inspect before you click. Check sender details and hover over links before engaging.
- Report rather than ignore. A suspicious message that you simply delete helps nobody else; reporting through the proper channel protects colleagues.
Domain 4: Use the Internet Securely (28%)
This domain shares the top weight and covers the everyday browsing, connectivity and AI-tool habits of a typical employee.
Core topics
Judging web content and connections safely.
- Suspicious URLs: misspelled domains, odd subdomains and look-alike addresses.
- HTTPS limitations: the padlock means the connection is encrypted, not that the site is trustworthy. Criminals use HTTPS too.
- Public Wi-Fi: understand the risks of open networks and prefer safer alternatives for sensitive activity.
- Home networks and remote work: secure router settings and separating work from personal use.
- Cloud use: sharing and storing work information responsibly in approved services.
Generative AI hygiene
This is one of the most distinctive parts of CBS-510. Candidates should be able to explain:
- Privacy: why sensitive information should not be entered into AI prompts, since prompts may be stored or used beyond your control.
- Hallucinations: AI tools can produce confident but false output, so important facts must be verified before use.
- Intellectual property: generated content and the material you feed in can raise ownership and confidentiality concerns.
Key Takeaway
The padlock icon proves encryption, not legitimacy. If a question presents a convincing-looking HTTPS site with a lookalike domain, the lookalike domain is the red flag that matters.
Domain 3: Secure Devices (24%)
Here the exam shifts from judgment about people and websites to the hygiene of the hardware and software you use every day.
Device security essentials
The basics must be automatic.
- Multi-factor authentication (MFA): a second proof of identity dramatically reduces the damage of a stolen password.
- Password managers: let you use long, unique passwords without memorizing them.
- Updates: patching closes known vulnerabilities that attackers actively exploit.
- Backups: your recovery path after malware, loss or failure.
- Malware awareness: know how infections arrive and what suspicious device behavior looks like.
- BYOD: personal devices used for work require care about what data lives on them and how they are protected.
Why these pair together
Questions in this domain often test whether you understand layering. A strong password helps, MFA backs it up, updates reduce the chance of compromise, and backups limit the damage if something still goes wrong. If an answer choice treats one control as a complete solution, it is usually the wrong one.
Domain 1: Use Technology Responsibly (20%)
The lightest-weighted domain is still worth roughly one question in five, and it frames the mindset for everything else: you are a participant in your organization's security, not a bystander.
- Understand why security matters to you personally and to your employer.
- Follow organizational policy on acceptable technology use rather than improvising.
- Handle information with care, distinguishing what is sensitive from what is routine.
- Report incidents promptly. Incident reporting appears in the supported coverage, and the exam consistently favors speed and transparency over quietly hoping a problem goes away.
Cost, Access and Eligibility Facts
Registration and prerequisites
There are no formal registration prerequisites, no application fee, no supporting documentation and no eligibility verification. CertNexus recommends familiarity with everyday business computing, the web and email, which describes most working adults. The full picture is in CyberSAFE Requirements 2026.
What the published price actually covers
The published price is USD 15.17 for the CBS-510 Student Digital Course Bundle (SKU CNX0024SEBU2). This is a courseware-bundle price, not a standalone exam-only fee, so avoid describing it as "the exam cost." The course access key includes the CHOICE credential process, which is how the assessment and badge are delivered. Employers and training providers may package access differently, so confirm what your own purchase includes. For the complete pricing picture, read the CyberSAFE Certification Cost breakdown.
The Version Trap: CBS-510 vs. CBS-410
This is the single most common source of confusion for candidates researching the credential. The current assessment is CBS-510. However, the issuer's page also retains a notice about the earlier CBS-410, describing it as active and expected to retire in Q1 2026. That notice is stale and does not confirm an actual retirement date.
| Item | CBS-510 (current) | CBS-410 (legacy) |
|---|---|---|
| Positioning | Cyber Safety in the Age of AI | Earlier CyberSAFE version |
| Blueprint | Version 1.0, October 10, 2025 | February 8, 2022 |
| Use for prep? | Yes | Only for historical comparison |
The rule: prepare from CBS-510 materials and do not blend the two sets of objectives. Older study notes, forum posts and flashcards may reference the 2022 blueprint, and its content emphasis differs from the AI-focused current version. Always confirm the code on your materials.
A Domain-Ordered Review Plan
Because the credential is short and unlimited-retake, a compact plan is enough. The sequencing below is built around the blueprint weights rather than generic advice.
Domain 2 and Domain 4 first
- Together these account for 56% of the assessment, so front-load them.
- Drill the phishing, smishing, vishing, deepfake and voice-cloning distinctions.
- Practice judging suspicious URLs and explaining HTTPS limitations.
Domain 3, then Domain 1
- Cover MFA, password managers, updates, backups, malware and BYOD.
- Finish with responsible-use policy and incident reporting.
- Run a full practice set and review every missed multiple-response item.
Candidates often ask whether a credential this light is worth the effort. The answer depends on your goals; the ROI analysis and the realistic CyberSAFE jobs overview help frame that decision. When you are ready to test yourself under realistic conditions, take a timed run on the CyberSAFE practice test site.
Cheat Sheet FAQ
The assessment has 25 questions, a mix of multiple-choice and multiple-response items. You need 80%, which is 20 correct answers, to pass.
Resist Social-Engineering Attacks and Use the Internet Securely are tied for the largest weight at 28% each. Secure Devices follows at 24%, and Use Technology Responsibly at 20%.
Yes. Retakes are unlimited. Use any unsuccessful attempt to identify which domains need more review before trying again.
No. That figure is the published price of the CBS-510 Student Digital Course Bundle, a courseware package that includes the CHOICE credential process. It is not a standalone exam-only fee, and there is no separate application fee or eligibility verification.
No. CBS-410 is the legacy version, and its 2022 blueprint differs from the current CBS-510 objectives. A stale notice on the issuer page does not confirm a retirement date, but you should still prepare from CBS-510 only. If you want broader context on the credential, CyberSAFE Certification covers the overview.