CompTIA β’ CAS-005
CompTIA SecurityX (formerly CASP+) is an advanced-level cybersecurity certification for senior security engineers and architects that validates the ability to design, implement, and integrate secure solutions across complex enterprise environments. It covers governance, risk, compliance, security architecture, engineering, and operations.
Questions
599
Duration
165 minutes
Passing Score
Pass/Fail
Difficulty
ProfessionalLast Updated
Apr 2026
CompTIA SecurityX (CAS-005), launched on December 17, 2024, is the successor to CompTIA CASP+ (CAS-004) and represents the capstone certification in the CompTIA Cybersecurity Career Pathway. It validates advanced technical skills required to conceptualize, engineer, integrate, and implement secure solutions across complex enterprise environments β encompassing security architecture, engineering, operations, and governance, risk, and compliance. The certification is vendor-neutral, ANSI-accredited to ISO 17024 standards, and approved under DoD 8140/8570 as a baseline for IAT Level III, IAM Level II, and IASAE Levels I and II.
Unlike many cybersecurity certifications that focus on managing security programs, SecurityX emphasizes hands-on technical depth. Candidates must demonstrate proficiency in designing hybrid and multi-cloud secure architectures, applying advanced cryptographic technologies, automating security operations, and leading incident response across enterprise-scale environments. The exam also addresses the security implications of emerging technologies such as artificial intelligence, containerization, and CI/CD pipelines.
SecurityX is designed for senior security engineers and security architects who are responsible for designing, implementing, and managing security solutions rather than simply administering them. Ideal candidates typically hold roles such as Security Architect, Senior Security Engineer, Security Operations Lead, Security Integration Engineer, or Systems Requirements Planner.
The certification is also aligned with multiple NICE Cybersecurity Workforce Framework work roles and DoD 8140 positions, making it particularly relevant for professionals in government, defense contracting, and federal agency environments. Candidates should have substantial hands-on experience and be operating at a level where they are making architectural decisions and leading security initiatives, not just executing them.
CompTIA does not enforce formal prerequisites for CAS-005, but recommends a minimum of 10 years of general hands-on IT experience, including at least 5 years of hands-on technical security experience. Candidates are expected to possess knowledge equivalent to CompTIA Network+, Security+, CySA+, Cloud+, and PenTest+ β either through those certifications or equivalent professional experience.
In practice, candidates who attempt SecurityX without a strong foundation in network security, cryptography, cloud infrastructure, and security operations often find the exam extremely challenging. Professionals who have already earned Security+ and CySA+ (or CISSP/equivalent) and are working in senior technical security roles are the most common and well-prepared candidates.
The CAS-005 exam consists of a maximum of 90 questions, delivered in a maximum of 165 minutes. Question types include both multiple-choice and performance-based questions (PBQs), where candidates must interact with simulated environments or scenarios to demonstrate applied skills. The exam is available in English via online proctoring through Pearson VUE's OnVUE platform or at a physical Pearson VUE testing center.
The exam uses a pass/fail grading model β no scaled score is reported. CompTIA does not publish a numeric passing threshold for SecurityX; candidates simply receive a pass or fail result. The certification is valid for three years and can be renewed through CompTIA's Continuing Education (CE) program by earning 75 CEUs within the three-year cycle.
SecurityX holders command some of the highest salaries in the CompTIA certification portfolio. The average reported salary for SecurityX practitioners is approximately $165,000, with security architects and senior security engineers typically earning between $155,000 and $200,000+ depending on sector and geography. The certification's DoD 8140/8570 approval makes it a direct pathway to roles within federal agencies and defense contractors β organizations including General Dynamics, Booz Allen Hamilton, and Leidos actively seek candidates with this credential.
As the capstone of the CompTIA Cybersecurity Career Pathway, SecurityX is positioned above Security+, CySA+, and PenTest+ and signals to employers that a candidate operates at the architect and integrator level rather than the analyst or administrator level. Compared to alternatives like CISSP (which is management-focused) or OSCP (which is offense-focused), SecurityX occupies a distinct niche as a hands-on, vendor-neutral credential validating advanced defensive architecture and engineering skills. Employers in both the public and private sectors β including Target, Ricoh, and Exxon Mobil β recognize the certification for senior technical security hiring.
1. Litware is implementing software supply chain security for their development process. They need to provide transparency into all components used in their applications, including transitive dependencies, to comply with federal software requirements. Which approach should they implement? (Select one!)
2. Tailspin Toys is conducting a Business Impact Analysis (BIA) for critical business processes. The analysis reveals that their e-commerce platform has an RTO of 4 hours, RPO of 30 minutes, and Work Recovery Time (WRT) of 2 hours. The Maximum Tolerable Period of Disruption (MTPD) is 8 hours. Which of the following statements is correct regarding these BCP/DRP metrics? (Select one!)
3. Fabrikam's AI security team is reviewing the deployment of a large language model integrated into their customer service platform. A security researcher reports that malicious users have been crafting inputs that cause the LLM to ignore its system prompt instructions and execute unauthorized actions on backend systems. Which OWASP LLM Top 10 vulnerability does this represent, and what is the PRIMARY mitigation? (Select one!)
4. Northwind Software is implementing Software Composition Analysis (SCA) in its CI/CD pipeline. The development manager wants to understand what SCA will detect. Which security issues does SCA identify? (Select two!)
Select all that apply5. Northwind's enterprise risk management team is performing a quantitative risk assessment for a public-facing web application. The asset is valued at $1,500,000. A successful DDoS attack is estimated to damage 40% of the asset value. Historical data shows that successful DDoS attacks occur approximately 3 times per year. A cloud-based DDoS mitigation service costs $60,000 annually and is expected to reduce the attack frequency to 0.5 attacks per year. What is the Return on Security Investment (ROSI) for the DDoS mitigation service? (Select one!)
All exams included β’ Cancel anytime