CertGrid
Security Study Guide

CompTIA SecurityX (CAS-005, formerly CASP+) Study Guide

CompTIA SecurityX (CAS-005, formerly CASP+) validates advanced practitioner-level skills for senior security engineers and architects who design, implement, and govern enterprise security across hybrid and cloud environments. The exam runs up to 165 minutes with a maximum of about 90 multiple-choice and performance-based questions, scored on a scale where 750 is passing. It covers four domains: Governance/Risk/Compliance, Security Architecture, Security Engineering, and Security Operations.

Domain 1: Governance, Risk, and Compliance

Key concepts you must know · 162 practice questions

Domain 2: Security Architecture

Key concepts you must know · 149 practice questions

Domain 3: Security Engineering

Key concepts you must know · 158 practice questions

Domain 4: Security Operations

Key concepts you must know · 173 practice questions

CompTIA SecurityX (CAS-005, formerly CASP+) exam tips

Study guide FAQ

Is SecurityX (CAS-005) the same as CASP+?

Yes. SecurityX is the rebranded continuation of CompTIA Advanced Security Practitioner (CASP+). CAS-005 is the current exam version and replaced CAS-004; the rebrand to SecurityX reflects its place in CompTIA's expert-tier Xpert series. Existing CASP+ certifications remain valid.

How is SecurityX scored and what do I need to pass?

There is no published number of correct answers required. The exam is scored on a scaled range and a 750 is passing. It contains up to about 90 questions (a mix of multiple-choice and performance-based simulations) and you have up to 165 minutes. The exam is pass/fail, not graded on a percentage.

What experience should I have before attempting it?

CompTIA recommends at least 10 years of general IT experience with a minimum of 5 years of hands-on technical security experience. It is an advanced practitioner-level exam aimed at senior security engineers and architects, so prior knowledge equivalent to Security+ and CySA+ is assumed rather than re-tested at the basic level.

What is the difference between SecurityX and CISSP?

SecurityX is hands-on and technical, emphasizing engineering, architecture, and operations with performance-based labs, and has no formal experience prerequisite to sit the exam. CISSP (ISC2) is broader and more managerial across eight domains and requires five years of cumulative paid work experience to be fully certified. Many practitioners use SecurityX to validate deep technical implementation skill.