CyberSAFE logo
Focused certification exam prep
Start practice

CyberSAFE Exam Domains 2026: Complete Guide to All 4 Content Areas

TL;DR
  • CyberSAFE: Securing Assets for End Users is a CertNexus credential assessed through exam CBS-510 across four weighted domains.
  • Resisting social engineering and using the Internet securely each carry 28%, making them the two largest domains.
  • The assessment has 25 multiple-choice/multiple-response questions, and you need 80% (20 of 25) to pass.
  • Generative-AI risks, deepfakes, and voice cloning appear in the current blueprint, so older CBS-410 materials are not enough.

How the CBS-510 Blueprint Is Organized

CyberSAFE: Securing Assets for End Users is an end-user security credential from CertNexus. It is aimed at everyday workers rather than security engineers, which shapes everything about the exam: the questions test whether you can recognize a risky situation and pick the safe response, not whether you can configure a firewall. The current assessment is exam CBS-510, marketed as CyberSAFE: Cyber Safety in the Age of AI, and its content is defined by the CyberSAFE (CBS-510) Exam Blueprint, version 1.0, issued October 10, 2025.

That blueprint divides the assessment into four weighted domains. This guide walks through each one, explains what kinds of scenarios fall under it, and shows how to allocate your preparation time. If you want the broader picture first, start with what CyberSAFE certification is and then return here for the domain-level detail.

Domain Weights at a Glance

The weights tell you where the question volume is likely to concentrate. With only 25 questions in total, each domain contributes a small handful, so there is little room to ignore any single area.

DomainWeightCore Focus
1. Use Technology Responsibly20%Responsible handling of technology, including generative AI, privacy, and intellectual property
2. Resist Social-Engineering Attacks28%Phishing, smishing, vishing, deepfakes, voice cloning
3. Secure Devices24%MFA, password managers, updates, backups, malware, BYOD
4. Use the Internet Securely28%Suspicious URLs, HTTPS limitations, cloud use, public Wi-Fi, home networks, remote work
Why the weights matter: Domains 2 and 4 together account for 56% of the blueprint. A candidate who is comfortable with technology in general but weak on spotting social-engineering tactics or judging whether a link and connection are safe is exposed in more than half of the assessment.

Domain 1: Use Technology Responsibly (20%)

The smallest domain by weight is also where the "Age of AI" branding shows most clearly. It covers how end users should behave when working with modern tools, particularly generative AI, and how their choices affect privacy, ownership of content, and the organization's data.

What candidates must understand

This domain asks you to apply good judgment to everyday technology decisions rather than recite definitions.

  • Sensitive information in AI prompts: recognizing what should never be pasted into a generative-AI tool, such as confidential business data or personal details.
  • Generative-AI privacy: understanding that what you submit to an AI service may not stay private.
  • Hallucinations: knowing that AI output can be confidently wrong and must be verified before being relied upon or shared.
  • Intellectual property: respecting ownership concerns when creating, copying, or reusing content, including AI-generated material.

Typical scenario angles

Expect situational wording: an employee wants to speed up a task with an AI assistant, and you must identify which data is safe to include and which is not. Or a colleague shares an AI-generated summary with unverified claims, and the right answer involves checking it first. The common thread is accountability: the user remains responsible for what they submit and what they pass along.

Domain 2: Resist Social-Engineering Attacks (28%)

Tied for the heaviest weight, this domain is where CyberSAFE earns its reputation as a practical awareness credential. Social engineering targets people instead of systems, so the whole domain is about recognizing manipulation and responding correctly.

Attack types you should be able to tell apart

The blueprint-supported coverage names several delivery channels, and exam questions often hinge on identifying which one is in play.

  • Phishing: deceptive email designed to steal credentials or push a harmful action.
  • Smishing: the same idea delivered by text message.
  • Vishing: voice-based attacks, usually by phone call.
  • Deepfakes: synthetic audio, image, or video used to impersonate someone convincingly.
  • Voice cloning: AI-generated imitation of a real person's voice, often used to add credibility to a fraudulent request.

Recognizing the pattern, not just the label

Most questions in this domain reward pattern recognition. Look for urgency, pressure to bypass normal procedure, requests for credentials or payment, unexpected attachments, and mismatches between a sender's claimed identity and the channel used. A realistic scenario might describe a call that sounds exactly like a manager asking for an urgent favor; the safe response is to verify through a separate, trusted channel rather than act on the voice alone.

Don't let AI realism fool you: Deepfakes and voice cloning are included because a familiar face or voice is no longer proof of identity. When a question describes a convincing but unusual request, the strongest answer typically involves independent verification and reporting, not trusting how authentic it sounds.

Reporting is part of this domain's logic too. Knowing how and when to report a suspected attack ties into the incident-reporting topics in the blueprint-supported coverage. For a quick reference to the attack terminology, the CyberSAFE cheat sheet is a useful companion.

Domain 3: Secure Devices (24%)

This domain moves from human manipulation to the hygiene of the devices you use daily. The questions are practical: which habit protects a device, which setting reduces risk, and which action leaves a gap.

High-value device security topics

These are the building blocks the exam draws on.

  • Multi-factor authentication (MFA): why a second factor limits the damage when a password is stolen.
  • Password managers: how they support unique, strong credentials without relying on memory or reuse.
  • Updates: why timely patching closes known weaknesses.
  • Backups: how regular backups protect against data loss and recovery from attacks such as ransomware.
  • Malware: recognizing infection symptoms and the behaviors that invite it.
  • BYOD (bring your own device): the added risk of mixing personal and work use on one device.

How scenarios are framed

You may be asked to choose the best next step after noticing odd device behavior, or to pick the most effective habit from a list of plausible ones. Because several options can sound reasonable, read for the answer that most directly reduces risk. Multiple-response items in this domain may expect you to select every correct protective measure, so partial recognition is not enough.

Key Takeaway

For Domain 3, connect each control to the problem it solves: MFA to stolen passwords, updates to known vulnerabilities, backups to data loss, password managers to credential reuse. That mapping lets you answer unfamiliar scenarios by reasoning instead of memorizing.

Domain 4: Use the Internet Securely (28%)

The second 28% domain covers how you behave online and across the networks you connect through. It is broad, spanning the browser, the cloud, and the physical places you work from.

Topics inside this domain

The supported coverage lists several areas where candidates should be confident.

  • Suspicious URLs: spotting lookalike domains, odd spellings, and links that do not match their displayed text.
  • HTTPS limitations: understanding that a padlock or HTTPS connection means the traffic is encrypted, not that the site itself is trustworthy.
  • Cloud use: using cloud services and file sharing carefully, including thinking about what is shared and with whom.
  • Public Wi-Fi: recognizing the risks of untrusted networks in cafes, airports, and hotels.
  • Home networks: basic precautions for the network you use when working from home.
  • Remote work: carrying secure habits outside the office environment.
  • Incident reporting: knowing that suspected problems should be reported promptly rather than quietly ignored.

The HTTPS trap

One of the more instructive concepts here is the limit of HTTPS. Many people assume a secure-looking connection equals a safe site, and exam writers know it. A malicious site can use HTTPS as easily as a legitimate one, so the correct reasoning separates "the connection is encrypted" from "the destination is legitimate."

Because Domains 2 and 4 are so closely related, with phishing links bridging the two, studying them together reinforces both. For a view of how demanding the combined material feels in practice, see how hard the CyberSAFE exam is.

What the Question Format Means for Your Prep

The assessment contains 25 multiple-choice and multiple-response questions, and the passing score is 80%, which means 20 correct out of 25. That threshold is demanding relative to the small question count: you can afford only five misses. Retakes are unlimited, so a miss is not final, but you should still aim to pass cleanly. Our passing score breakdown goes deeper on what 80% means in practice.

Timing is worth understanding accurately. CertNexus materials estimate completion in the range of roughly 20 to 45 minutes, and the assessment table cites a 20-to-40-minute average. Treat these as completion estimates rather than a verified fixed exam timer. The half-day training is a separate thing from the time you spend on the assessment itself.

  • Read every option on multiple-response items. These can require selecting more than one correct choice, and missing one counts against you.
  • Look for the safest realistic action. The questions favor sound, proportionate end-user behavior over dramatic or technical responses.
  • Watch for absolute language. Statements implying something is always safe, such as any HTTPS site, are usually traps.

Avoiding the CBS-410 and CBS-510 Mix-Up

An important preparation pitfall: the issuer's page still carries a notice about an earlier version, CBS-410, saying it is active and expected to retire in Q1 2026. That notice is stale and does not confirm an actual retirement date, so do not treat it as settled fact. More importantly, CBS-410 and CBS-510 have different objectives, and you should not blend them when studying.

AspectCBS-510 (current)CBS-410 (legacy)
Marketing titleCyberSAFE: Cyber Safety in the Age of AIEarlier CyberSAFE offering
Blueprint sourceVersion 1.0, issued October 10, 2025Dated February 8, 2022
AI-related contentProminent: prompts, hallucinations, deepfakes, voice cloningNot the focus of this guide
Use for studyPrimary source for this articleComparison only, do not mix objectives

If you encounter older study notes that omit generative-AI content, treat them as incomplete for CBS-510. Confirm which assessment you are actually sitting before you start. Our exam dates and scheduling guide covers how to check the current offering.

Sequencing the Domains in a Short Study Plan

Because the content is practical and the exam is short, a compact plan works. The goal is to order the domains by weight and by how much they build on one another.

Week 1

Domain 2 first

  • Learn the five attack channels: phishing, smishing, vishing, deepfakes, voice cloning
  • Practice spotting urgency, impersonation, and verification cues
Week 2

Domain 4 next

  • Study suspicious URLs and the limits of HTTPS
  • Review public Wi-Fi, home networks, remote work, and cloud sharing
Week 3

Domains 3 and 1

  • Map controls to threats: MFA, password managers, updates, backups, BYOD
  • Cover AI prompts, hallucinations, privacy, and intellectual property
Week 4

Mixed review

  • Take full practice sets to test 25-question stamina
  • Revisit any domain where you miss multiple-response items

Starting with the 28% domains front-loads the material that carries the most weight. For a fuller plan, the CyberSAFE study guide lays out preparation in more detail, and you can test yourself on the CyberSAFE practice test site as you progress.

Access, Cost and Eligibility Basics

CyberSAFE is delivered online, through CHOICE or the issuer's e-learning offering. There are no formal registration prerequisites, no application fee, no supporting documentation, and no eligibility verification. Familiarity with everyday business computing, the web, and email is recommended, not required. The details are covered in CyberSAFE requirements.

On cost, the published price is USD 15.17 for the CBS-510 Student Digital Course Bundle. This is a courseware-bundle price, not a standalone exam-only fee, and the course access key includes the CHOICE credential process. For a full picture of what you might pay, see the CyberSAFE certification cost breakdown.

Training versus assessment: The half-day training and the assessment are separate. Completing the course content does not itself equal passing; you still need 20 of 25 on the assessment, and unlimited retakes mean a first-attempt miss is recoverable.

Supplementary preparation material exists in the form of CertNexus's CNX0024 course outline. Its lesson headings are an unweighted preparation curriculum, not a separate exam-domain structure and not a claim of exhaustive exam coverage, so rely on the four blueprint domains when planning. Before investing effort, you may also want to weigh the value using whether the CyberSAFE certification is worth it.

Frequently Asked Questions

How many domains are on the CyberSAFE CBS-510 exam?

The CBS-510 blueprint defines four weighted domains: Use Technology Responsibly (20%), Resist Social-Engineering Attacks (28%), Secure Devices (24%), and Use the Internet Securely (28%).

Which domains carry the most weight?

Resist Social-Engineering Attacks and Use the Internet Securely are jointly largest at 28% each, together making up 56% of the blueprint.

How many questions are on the exam and what score do I need?

The assessment has 25 multiple-choice and multiple-response questions. The passing score is 80%, which equals 20 correct answers out of 25. Retakes are unlimited.

Does the exam cover AI topics?

Yes. The CBS-510 coverage includes generative-AI privacy and hallucinations, sensitive information in AI prompts, intellectual property, deepfakes, and voice cloning, so older materials that omit these are incomplete.

Are there prerequisites to take CyberSAFE?

There are no formal registration prerequisites, application fee, supporting documentation, or eligibility verification. Familiarity with everyday business computing, the web, and email is recommended.

Ready to pass your CyberSAFE exam?

Put this into practice with free CyberSAFE questions across every exam domain.