AI Readiness for Information Security
The AI Readiness for Information Security exam proves you can run detection, prevention, and response for the new threat surface created by AI: prompt injection, model supply chain, DLP for AI prompts, and identity for agent workloads.
How the credential happens
- 01
Pay $10.00
Pay once via Paddle. No subscription.
- 02
50 questions · 45 min
Server-timed. Randomized question + option order per attempt.
- 03
Pass at 40 / 50
Server scores instantly. No partial-credit games.
- 04
Retry for $2
Available 2 hours after submit. Fresh question subset on each retry.
- 05
Public certificate
Verify URL with issuance date, recipient, live status.
See a sample verify page →
Who this cert is for
If you're early in your security career
Every team you join now has an AI initiative the security team did not ask for. Junior analysts who can name the prompt-injection vector, the LLM supply-chain risk, and the DLP gap when employees paste into ChatGPT are the ones who get pulled onto the AI-risk working group. This cert is the verifiable signal that you arrived already speaking the vocabulary.
If you're a working security pro
The CISO is being asked monthly about AI threats. The IAM policy assumed humans, not agents. The DLP policy assumed file uploads, not LLM prompts. Your job is to update all of the above without the security org becoming the team that blocks every AI initiative. This cert is proof you can be the practitioner who knows where to say yes, where to say no, and how to ship the guardrails that let the business move.
What you’ll prove
- Name and triage prompt-injection attacks against AI agents that read inbound content (email, tickets, documents).
- Build a DLP posture that prevents confidential data from being pasted into external AI tools while offering a sanctioned alternative.
- Assess the supply-chain risk in a third-party LLM provider: breach scenarios, term changes, shutdowns, and your operational dependency in each.
- Design identity and access for AI agents acting on behalf of humans, with the audit trail that survives incident review.
- Run incident response for AI-specific events (model abuse, prompt-injection exploit, data exfiltration through an agent).
What the exam covers
- AI threat landscape and prompt injection (6 questions)
- Phishing, social engineering, security awareness (5 questions)
- DLP, secrets, AI content risks (7 questions)
- AI supply chain and third-party integrations (5 questions)
- Identity, access, agent workloads (3 questions)
- Model security, threat modeling, vuln mgmt (7 questions)
- Incident response, logging, audit (4 questions)
- AI Act and regulation, governance, metrics (7 questions)
- Cloud security, developer risk, future of security (6 questions)
Sample questions
Real questions from the bank, in the same shape you’ll see in the exam. Correct answers are not shown.
- Q01Prompt injection
Your customer support AI processes incoming emails to draft replies. Highest prompt-injection risk:
- Slow drafts.
- Attacker embeds instructions in their email that hijack the agent into exfiltrating internal data or taking unauthorized actions.
- Wrong tone of voice.
- Spelling errors in the reply.
- Q02AI supply chain
Your team is integrating a third-party LLM. Most important supply-chain risk:
- API latency.
- What happens if the provider gets breached, changes terms, or shuts down: your data exposure and operational dependency in each of those scenarios.
- Cost per token.
- UX design of the provider's dashboard.
- Q03Data-loss prevention
Most important DLP control for the AI era:
- Block all email attachments.
- Visibility and control over what data goes into AI prompts. At minimum, blocking confidential data classes from external AI tools, with a sanctioned alternative.
- Disable USB ports.
- Disable employee browsers.
Honest tradeoffs
- · Not a CISSP, OSCP, or CompTIA Security+ replacement.
- · Not a vendor cert. No Microsoft Security, no Crowdstrike, no Palo Alto exam.
- · Not a guarantee any single AI tool deployment will be safe in your environment.
It is proof you can extend a security program to cover AI agents, AI vendors, and AI threat patterns without forcing the business to a halt.
Frequently asked
- Does this replace CISSP, CISM, or other security certs?
- No. Take this alongside whichever broad credential your role requires. The verify URL signals you have the AI-specific judgment that general certs do not yet cover in depth.
- Do I need to know how LLMs work internally?
- No. The exam tests the defender's perspective: threats, controls, response. You do not need to fine-tune a model to answer the questions.
- Is this for blue team, red team, or both?
- Primarily blue team and security architecture. Red-team work on AI systems is a different specialty that this cert does not test in depth.
- What if I fail?
- Pay $2 to retry once after the 2-hour gate. The retry pulls fresh questions.
- Is this region-specific?
- The questions cover principles that apply broadly. The AI Act and emerging-regulation section is touched at the level a practitioner should know, not at the depth of a compliance role.
- How long is it valid?
- One year. The threat landscape moves; renewal exams pull from the refreshed bank.
Before you start
- · You’ll capture the name on your certificate before the exam starts. It cannot be edited after publishing.
- · 45 min hard timer. The server auto-submits whatever’s answered when it expires.
- · One attempt per purchase. Fail it? Pay $2 to retry this cert once after the 2-hour gate. Pass it? You'll receive a 50% off coupon valid 30 days for your next Readiness cert.
- · Read the honor code. AI-assisted attempts may be reviewed and certificates revoked.
What this changes for you
Half the dev team is pasting secrets into AI assistants without realizing it; the other half is filing tickets about prompt-injection demos. You are the security person who has to draw the policy and you have not yet found the time to write it from the model up.
You can name the data classes you allow in AI tools, the egress controls, the audit trail, and the failure modes from prompt injection to model-extraction. The CISO trusts your AI security policy because you have the discipline on paper.
Exam integrity & refund policy
This is a proctored exam. By purchasing and beginning it, you agree to the honor code and to automated, in-browser integrity monitoring of your session. Conduct that breaches the integrity policy, including leaving the exam window, switching tabs or applications, using external help or AI tools, or copying, cutting, or pasting exam content, is recorded. Repeated violations result in immediate forfeiture of your exam attempt.
Exam fees are non-refundable once an attempt has begun, including attempts ended early for integrity violations. jusCode Academy may withhold, suspend, or revoke any certificate obtained through conduct that violates this policy, with or without prior notice.
Your final price is computed at checkout. First-ever Readiness is $5, 50%-off coupon on completion of any prior cert. $2 paid retry per cert if you fail.
Related certifications
AI General Security
Spot the new attack surface around AI.
45 min · 50 questions
AI Readiness for IT Operations
AI in your help desk and runbooks.
45 min · 50 questions
AI Ethics
Reason carefully about bias, safety, transparency, and responsible use.
45 min · 50 questions