CompTIA SecurityX is CompTIA’s expert-level cybersecurity certification, and it’s built for people who already design, engineer, and defend enterprise environments. If you’re used to exams that reward memorized definitions, SecurityX can feel like a different animal. Its questions put you in the architect’s or senior engineer’s seat and ask what you would build, fix, or recommend.
In this guide, we’ll walk you through the exam format, all four domains and their weights, the official resources worth downloading, and the questions candidates ask most often.
What Is the CompTIA SecurityX Exam?
SecurityX is the new name for the certification formerly known as CompTIA Advanced Security Practitioner (CASP+). The rename arrived with the current exam version, CAS-005, which launched on December 17, 2024. SecurityX is part of CompTIA’s expert-level “X” credentials, sitting above Security+, CySA+, and PenTest+ in CompTIA’s cybersecurity pathway.
Where Security+ checks that you understand core security concepts, SecurityX checks that you can apply them across a whole enterprise. Expect scenarios about hybrid and cloud architecture, Zero Trust, identity troubleshooting, cryptography choices, threat hunting, incident response, and governance. Many questions ask for the best technical or strategic decision, not just a correct fact.
What Is the CompTIA SecurityX Exam Format?
Here’s the exam at a glance, based on the CompTIA SecurityX certification page and the official exam objectives:
- Exam code: CAS-005.
- Questions: A maximum of 90 questions.
- Question types: Multiple-choice and performance-based questions (PBQs), which are hands-on simulations such as configuring settings, analyzing logs, or placing controls in an architecture.
- Time: A maximum of 165 minutes.
- Scoring: Pass/fail only. Unlike Security+ and most other CompTIA exams, SecurityX does not report a scaled score.
- Delivery: Pearson VUE test centers or online proctored through OnVUE (see CompTIA’s testing options page).
- Language: English.
- Results: You see your pass/fail result as soon as you finish.
- Recommended experience: At least 10 years of general hands-on IT experience, including 5 years of hands-on security experience. This is a recommendation, not a formal prerequisite.
With 165 minutes for up to 90 questions, you average a little under two minutes per question. PBQs often take much longer, so many candidates flag them, work through the multiple-choice questions, and come back with the remaining time.
What Content Outline Does the CompTIA SecurityX Exam Use?
The current exam follows the CompTIA SecurityX Certification Exam Objectives (CAS-005). It organizes the exam into four domains and 23 objectives. The approximate question counts below are our estimates, calculated from CompTIA’s percentages and a 90-question exam.
- Domain 1.0, Governance, Risk, and Compliance: 20% (about 18 questions)
- Domain 2.0, Security Architecture: 27% (about 24 questions)
- Domain 3.0, Security Engineering: 31% (about 28 questions)
- Domain 4.0, Security Operations: 22% (about 20 questions)
If you studied for CASP+ (CAS-004), note that the domains have changed. The old “Security Engineering and Cryptography” domain is now simply “Security Engineering,” with cryptography folded into it. GRC moved to Domain 1, and the new outline adds topics such as AI adoption risks and Zero Trust as their own objectives.
Domain 1.0: Governance, Risk, and Compliance (20%)
This domain covers the business side of security leadership: how programs are governed, how risk is measured and treated, and how laws and frameworks shape security strategy.
- Implement governance components, including policies, standards, and procedures; RACI matrices; frameworks such as COBIT and ITIL; change and configuration management; and GRC tools.
- Perform risk management activities, including quantitative and qualitative assessment, risk appetite and tolerance, third-party and supply chain risk, business continuity, and breach response.
- Explain how compliance affects security strategy, from PCI DSS, ISO/IEC 27000, SOC 2, and NIST CSF to privacy laws such as GDPR, CCPA, LGPD, and COPPA.
- Perform threat modeling with MITRE ATT&CK, CAPEC, the Cyber Kill Chain, the Diamond Model, STRIDE, and OWASP.
- Summarize security challenges of AI adoption, such as prompt injection, training data poisoning, model theft, and excessive agency.
Study tip: Know the difference between an audit, an assessment, and a certification, and be ready to pick the right threat-modeling framework for a described goal.
Domain 2.0: Security Architecture (27%)
Security Architecture is about designing environments that are secure from the start. You’ll decide where controls go, how systems stay available, and how identity, cloud, and Zero Trust fit together.
- Analyze requirements to design resilient systems, including placement of firewalls, IDS/IPS, WAFs, proxies, API gateways, and load balancers.
- Build security into the systems life cycle with SAST, DAST, IAST, RASP, software composition analysis, SBoMs, and CI/CD controls.
- Integrate controls into design, including DLP, data classification, centralized logging, and sensor placement.
- Apply security to access, authentication, and authorization systems: federation, SSO, access control models, and PKI architecture.
- Securely implement cloud capabilities such as CASBs, containers, serverless, API security, and the shared responsibility model.
- Integrate Zero Trust concepts, including continuous authorization, microsegmentation, SASE, and SD-WAN.
What questions look like: You might see a network diagram and be asked where to place a WAF or sensor, or choose the architecture change that best meets a stated business requirement.
Domain 3.0: Security Engineering (31%)
This is the largest and most hands-on domain. It focuses on implementing and troubleshooting the technologies that make an architecture work.
- Troubleshoot IAM issues involving SAML, OpenID, OAuth, Kerberos, 802.1X, MFA, secrets management, and conditional access.
- Enhance endpoint and server security with EDR, application control, HIPS, SELinux, and MDM.
- Troubleshoot network security issues, including IDS/IPS rules, DNSSEC, SPF, DKIM, DMARC, TLS errors, and cipher mismatches.
- Implement hardware security, including TPM, HSM, secure enclaves, Secure Boot, and measured boot.
- Secure specialized and legacy systems, including OT, SCADA, ICS, IoT, and embedded devices.
- Use automation (PowerShell, Bash, Python, IaC, SOAR, and SCAP) to secure the enterprise.
- Explain and apply advanced cryptography, including post-quantum cryptography, forward secrecy, envelope encryption, AEAD, homomorphic encryption, tokenization, and code signing.
Study tip: Many PBQs live here. Practice reading real log output and configuration snippets until you can spot a misconfiguration quickly.
Domain 4.0: Security Operations (22%)
Security Operations covers monitoring, analysis, and response: turning data into detections and handling what those detections find.
- Analyze data for monitoring and response, including SIEM tuning, behavior baselines, alert prioritization, and false positives and negatives.
- Analyze vulnerabilities and attacks such as injection, XSS, SSRF, CSRF, race conditions, TOCTOU, and deserialization, and recommend mitigations.
- Apply threat hunting and threat intelligence concepts, including STIX/TAXII, Sigma, YARA, Snort, honeypots, and ISACs.
- Analyze incident response data and artifacts, including malware sandboxing, reverse engineering, metadata analysis, and timeline reconstruction.
What questions look like: Expect a log excerpt or alert and a question about the most likely attack or the best mitigation. Matching a vulnerability to its specific fix (for example, parameterized queries for SQL injection) is a common pattern.
How Should You Use the SecurityX Blueprint to Study?
The objectives PDF is long, so use it as a checklist rather than something to read once. Here’s a simple approach:
- Take a mixed baseline. Answer a set of questions from all four domains before you start reviewing so you know where you actually stand.
- Rate every objective. Mark each of the 23 objectives as strong, developing, or weak.
- Weight your time. Security Engineering and Security Architecture make up 58% of the exam together, so weak spots there cost the most.
- Map every miss. Tie each missed question to an objective number, like 3.3 or 2.6, so patterns become obvious.
- Get hands-on. The objectives list suggested lab hardware and software. A home lab with virtual machines, a SIEM such as Security Onion, and a few scripts goes a long way for PBQs.
What Official Resources Should You Use?
- CompTIA SecurityX (CAS-005) Exam Objectives: The master list of what can be tested, including an acronym list and suggested lab equipment.
- CompTIA SecurityX certification page: Current format, pricing, and job role information.
- CompTIA testing policies: Rules for scheduling, ID, online proctoring, and retakes, available on the CompTIA test policies page.
Commonly used references:
- CompTIA CASP+ Practice Tests: Exam CAS-004 (ISBN 978-1119813057)
- CompTIA CASP+ Study Guide: Exam CAS-004 (ISBN 978-1119803164)
- CompTIA Advanced Security Practitioner (CASP+) CAS-004 Cert Guide, 3rd Edition (ISBN 978-0137348954)
Frequently Asked Questions About the CompTIA SecurityX Exam
What is the passing score for SecurityX?
There isn’t a published one. SecurityX is scored pass/fail with no scaled score, so you’ll simply see whether you passed.
Is SecurityX the same as CASP+?
Yes. SecurityX is the new name for CASP+, introduced with the CAS-005 exam. The content was also updated, so older CAS-004 materials won’t cover everything.
Are there prerequisites?
No formal prerequisites. CompTIA recommends at least 10 years of IT experience, including 5 years of hands-on security, plus Network+, Security+, CySA+, Cloud+, and PenTest+ or equivalent knowledge.
What happens if I don’t pass?
Under CompTIA’s retake policy, you can retake immediately after a first failed attempt. Before a third or later attempt, you must wait at least 14 calendar days. You pay the full exam price each time.
How long is the certification valid?
Three years. You can renew by earning 75 continuing education units (CEUs) in that cycle, passing the latest exam version, or using other CompTIA renewal options.
When will CAS-005 be replaced?
CompTIA estimates CAS-005 will retire in 2027, typically about three years after launch. Check the certification page before scheduling if your exam date is far out.
Start Preparing for the CompTIA SecurityX Exam With Pocket Prep
SecurityX rewards candidates who practice thinking like an architect, and that takes repetition. Pocket Prep’s CompTIA SecurityX practice questions include 1,430 questions with detailed explanations for every answer, plus a full-length mock exam to test your timing. Use the Weakest Subject quiz to go after your lowest-scoring domain and Missed Questions to lock in what you’ve learned. Stay consistent, and you’ll walk into exam day with confidence.