CompTIA · CAS-005
CompTIA SecurityX (formerly CASP+) is an advanced-level cybersecurity certification for senior security engineers and architects that validates the ability to design, implement, and integrate secure solutions across complex enterprise environments. It covers governance, risk, compliance, security architecture, engineering, and operations.
Practice Questions
599
≈ 6 practice exams
Duration
165 minutes
Passing Score
Pass/Fail
Difficulty
ProfessionalLast Updated
Apr 2026
Use this CAS-005 practice exam to prepare for CompTIA SecurityX (CAS-005) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 599 questions for CompTIA CAS-005, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Governance, Risk, and Compliance, Security Architecture, Security Engineering, Security Operations, and Cloud and Hybrid Environment Security. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
CompTIA SecurityX (CAS-005), launched on December 17, 2024, is the successor to CompTIA CASP+ (CAS-004) and represents the capstone certification in the CompTIA Cybersecurity Career Pathway. It validates advanced technical skills required to conceptualize, engineer, integrate, and implement secure solutions across complex enterprise environments — encompassing security architecture, engineering, operations, and governance, risk, and compliance. The certification is vendor-neutral, ANSI-accredited to ISO 17024 standards, and approved under DoD 8140/8570 as a baseline for IAT Level III, IAM Level II, and IASAE Levels I and II.
Unlike many cybersecurity certifications that focus on managing security programs, SecurityX emphasizes hands-on technical depth. Candidates must demonstrate proficiency in designing hybrid and multi-cloud secure architectures, applying advanced cryptographic technologies, automating security operations, and leading incident response across enterprise-scale environments. The exam also addresses the security implications of emerging technologies such as artificial intelligence, containerization, and CI/CD pipelines.
SecurityX is designed for senior security engineers and security architects who are responsible for designing, implementing, and managing security solutions rather than simply administering them. Ideal candidates typically hold roles such as Security Architect, Senior Security Engineer, Security Operations Lead, Security Integration Engineer, or Systems Requirements Planner.
The certification is also aligned with multiple NICE Cybersecurity Workforce Framework work roles and DoD 8140 positions, making it particularly relevant for professionals in government, defense contracting, and federal agency environments. Candidates should have substantial hands-on experience and be operating at a level where they are making architectural decisions and leading security initiatives, not just executing them.
CompTIA does not enforce formal prerequisites for CAS-005, but recommends a minimum of 10 years of general hands-on IT experience, including at least 5 years of hands-on technical security experience. Candidates are expected to possess knowledge equivalent to CompTIA Network+, Security+, CySA+, Cloud+, and PenTest+ — either through those certifications or equivalent professional experience.
In practice, candidates who attempt SecurityX without a strong foundation in network security, cryptography, cloud infrastructure, and security operations often find the exam extremely challenging. Professionals who have already earned Security+ and CySA+ (or CISSP/equivalent) and are working in senior technical security roles are the most common and well-prepared candidates.
The CAS-005 exam consists of a maximum of 90 questions, delivered in a maximum of 165 minutes. Question types include both multiple-choice and performance-based questions (PBQs), where candidates must interact with simulated environments or scenarios to demonstrate applied skills. The exam is available in English via online proctoring through Pearson VUE's OnVUE platform or at a physical Pearson VUE testing center.
The exam uses a pass/fail grading model — no scaled score is reported. CompTIA does not publish a numeric passing threshold for SecurityX; candidates simply receive a pass or fail result. The certification is valid for three years and can be renewed through CompTIA's Continuing Education (CE) program by earning 75 CEUs within the three-year cycle.
SecurityX holders command some of the highest salaries in the CompTIA certification portfolio. The average reported salary for SecurityX practitioners is approximately $165,000, with security architects and senior security engineers typically earning between $155,000 and $200,000+ depending on sector and geography. The certification's DoD 8140/8570 approval makes it a direct pathway to roles within federal agencies and defense contractors — organizations including General Dynamics, Booz Allen Hamilton, and Leidos actively seek candidates with this credential.
As the capstone of the CompTIA Cybersecurity Career Pathway, SecurityX is positioned above Security+, CySA+, and PenTest+ and signals to employers that a candidate operates at the architect and integrator level rather than the analyst or administrator level. Compared to alternatives like CISSP (which is management-focused) or OSCP (which is offense-focused), SecurityX occupies a distinct niche as a hands-on, vendor-neutral credential validating advanced defensive architecture and engineering skills. Employers in both the public and private sectors — including Target, Ricoh, and Exxon Mobil — recognize the certification for senior technical security hiring.
5 sample questions with answers and explanations. The full bank has 599 questions, enough for 6 full-length practice exams.
Preview — answers shown1. Contoso is analyzing a sophisticated APT intrusion using the Diamond Model. The investigation identified: adversary APT29, infrastructure including a C2 domain and compromised server IP, capability consisting of a custom PowerShell backdoor, and victim being Contoso's R&D division. How should the security team leverage this Diamond Model mapping to enhance intelligence and defense? (Select one!)
Explanation
The Diamond Model's analytical value comes from pivoting across its four core features to expand threat intelligence. Pivoting on infrastructure such as the C2 IP or domain can reveal other victim organizations sharing the same command and control infrastructure, additional campaigns, or related threat actor operations. Pivoting on capability such as the custom backdoor can identify related malware families, tool evolution patterns, shared code signatures, and TTP patterns enabling broader detection rules. Focusing exclusively on adversary attribution misses actionable technical indicators. Victim-focused defense is reactive and fails to leverage relational intelligence about attacker methods. Infrastructure is actually one of the easier elements for sophisticated actors to replace with new domains and IP addresses, making infrastructure blocking a low-durability control compared to TTP-based detection.
2. Litware Corporation is designing a cloud-delivered security architecture to replace their legacy VPN and branch office firewalls. The solution must provide Zero Trust network access to applications, secure web gateway functionality, cloud access security broker capabilities, and integrate with SD-WAN for optimized branch connectivity. Which architecture framework BEST describes this comprehensive approach? (Select one!)
Explanation
SASE (Secure Access Service Edge) converges SD-WAN networking capabilities with security services including ZTNA, CASB, SWG, and FWaaS, all delivered from the cloud. SSE includes only the security components (ZTNA, CASB, SWG, FWaaS) without the SD-WAN networking element. Since the requirement specifically includes SD-WAN integration, SASE is the correct answer. ZTNA and CASB are individual components within SASE, not comprehensive architecture frameworks.
3. Contoso operates across the European Union and processes personal data of EU citizens. The CISO is evaluating when a Data Protection Officer (DPO) must be appointed under GDPR. Which scenarios mandate DPO appointment? (Select three!)
Multiple correct answersExplanation
GDPR Article 37 mandates DPO appointment in exactly three scenarios: processing by public authorities or public bodies regardless of size, core activities requiring large-scale systematic monitoring of data subjects, and core activities involving large-scale processing of special categories of data including health, genetic, biometric, racial origin, religious beliefs, and criminal convictions. Company size, employee record count, revenue, and breach notification events do not trigger mandatory DPO requirements. Organizations that do not meet these thresholds may voluntarily appoint a DPO but are not required to do so.
4. Adatum needs to implement phishing-resistant multi-factor authentication for privileged user access to critical systems. The solution must prevent credential theft even if users are tricked into authenticating to malicious sites. Which authentication technology provides the strongest protection against phishing? (Select one!)
Explanation
FIDO2/WebAuthn provides the strongest phishing resistance because it uses public key cryptography where private keys never leave the authenticator device, and authentication is origin-bound — cryptographically tied to the specific domain. This prevents credentials from being used on malicious sites even if users are tricked into visiting them. SMS OTPs are vulnerable to SIM swapping and phishing, TOTP codes can be captured and replayed on malicious sites in real time, and push notifications are susceptible to MFA fatigue attacks where users approve fraudulent login prompts.
5. Fabrikam's security team is preparing for an ISO 27001:2022 certification audit. Which of the following best describes the difference between a Stage 1 and Stage 2 audit in the ISO 27001 certification process? (Select one!)
Explanation
In ISO 27001 certification, Stage 1 is a preliminary audit focusing on documentation review, ISMS scope, and organizational readiness. Stage 2 is the main certification audit where auditors evaluate the actual implementation and effectiveness of controls on-site. Both stages are conducted by external certification bodies.
CompTIA Project+ (PK0-005)
PK0-005 · 696 questions
CompTIA SecAI+ Certification (CY0-001)
CY0-001 · 600 questions
CompTIA Security+ (SY0-701)
SY0-701 · 700 questions
CompTIA Tech+ IT Fundamentals (FC0-U71)
FC0-U71 · 599 questions
CompTIA A+ Core 1 (220-1101)
220-1101 · 700 questions
CompTIA A+ Core 2 (220-1102)
220-1102 · 700 questions
$17.99
One-time access to this exam