CertGrid
Security Study Guide

CompTIA SecurityX (CAS-005, formerly CASP+) Study Guide

CompTIA SecurityX (CAS-005, formerly CASP+) validates advanced practitioner-level skills for senior security engineers and architects who design, implement, and govern enterprise security across hybrid and cloud environments. The exam runs up to 165 minutes with a maximum of about 90 multiple-choice and performance-based questions. The exam is pass/fail - CompTIA does not publish a numeric passing score. It covers four domains: Governance/Risk/Compliance, Security Architecture, Security Engineering, and Security Operations.

Objective-mapped study guide, aligned to current exam objectives · Reviewed Aug 2026 · Independent practice platform.

Real exam: Max 90 qs · 165 min

Domain 1: Governance, Risk, and Compliance

Key concepts you must know · 214 practice questions

Domain 2: Security Architecture

Key concepts you must know · 282 practice questions

Domain 3: Security Engineering

Key concepts you must know · 313 practice questions

Domain 4: Security Operations

Key concepts you must know · 231 practice questions

CompTIA SecurityX (CAS-005, formerly CASP+) exam tips

Study guide FAQ

Is SecurityX (CAS-005) the same as CASP+?

Yes. SecurityX is the rebranded continuation of CompTIA Advanced Security Practitioner (CASP+). CAS-005 is the current exam version and replaced CAS-004; the rebrand to SecurityX reflects its place in CompTIA's expert-tier Xpert series. Existing CASP+ certifications remain valid.

How is SecurityX scored and what do I need to pass?

There is no published passing score or number of correct answers required - CompTIA reports SecurityX as pass/fail. It contains up to about 90 questions (a mix of multiple-choice and performance-based simulations) and you have up to 165 minutes.

What experience should I have before attempting it?

CompTIA recommends at least 10 years of general IT experience with a minimum of 5 years of hands-on technical security experience. It is an advanced practitioner-level exam aimed at senior security engineers and architects, so prior knowledge equivalent to Security+ and CySA+ is assumed rather than re-tested at the basic level.

What is the difference between SecurityX and CISSP?

SecurityX is hands-on and technical, emphasizing engineering, architecture, and operations with performance-based labs, and has no formal experience prerequisite to sit the exam. CISSP (ISC2) is broader and more managerial across eight domains and requires five years of cumulative paid work experience to be fully certified. Many practitioners use SecurityX to validate deep technical implementation skill.

Related Security resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.