About the CompTIA SecurityX (CAS-005) exam
CompTIA SecurityX is CompTIA's advanced-level cybersecurity certification, the current evolution of what used to be called CASP+ (CompTIA Advanced Security Practitioner). CAS-005 is aimed squarely at hands-on security practitioners and architects who design, engineer, and operate enterprise security programs — it sits above Security+ and CySA+ in CompTIA's stackable certification path and is pitched as the highest CompTIA credential that stays technical rather than purely managerial.
CompTIA recommends candidates have around ten years of general hands-on IT experience, including roughly five years of broad hands-on security experience, along with knowledge equivalent to Network+, Security+, CySA+, Cloud+, and PenTest+. The exam covers security architecture, security engineering and cryptography, security operations, and governance/risk/compliance — deliberately blending deep technical configuration with organizational judgment calls.
SecurityX matters because it is one of the few vendor-neutral certifications recognized for the U.S. Department of Defense 8140 baseline at the advanced practitioner tier, and because it validates the kind of cross-cutting seniority (architecture plus engineering plus operations plus governance) that many senior security architect and engineering-lead roles expect but rarely test for directly.
CompTIA SecurityX (CAS-005) exam format at a glance
| Attribute | Detail (as of 2026, verify on the official page) |
|---|---|
| Exam code | CAS-005 |
| Number of questions | Maximum of 90 questions |
| Question types | Multiple-choice and performance-based questions (PBQs) |
| Duration | 165 minutes |
| Passing score | None — this exam has no scaled score; it is pass/fail only |
| Recommended experience | About 10 years of general hands-on IT experience, including 5 years of broad hands-on security experience |
| Cost | Not confirmed here; CompTIA's advanced-tier exams have historically been priced well above Security+ — check the official CompTIA store for the current voucher price |
| Delivery | Pearson VUE test center or online proctored from home |
| Validity | 3 years; renewable through CompTIA's Continuing Education (CE) program |
CompTIA SecurityX (CAS-005) domains & what they cover
The objectives are organized into four domains. The approximate weightings below reflect the published CAS-005 exam objectives; confirm current figures on the official page.
- Security Engineering (about 31%) — The largest domain: endpoint security configuration, enterprise mobility, cloud and virtualization security engineering, and enterprise-wide PKI and cryptographic solutions. This is where deep hands-on configuration knowledge is tested hardest.
- Security Architecture (about 27%) — Designing zero trust architecture across hybrid networks, secure cloud and virtualization solution design, and building in data protection, resilience, and business continuity from the architecture stage.
- Security Operations (about 22%) — Advanced threat management and threat hunting, vulnerability management, risk mitigation, incident response tactics, and digital forensics analysis.
- Governance, Risk, and Compliance (about 20%) — Measuring organizational cybersecurity resiliency, mapping to regulatory frameworks such as CMMC, PCI-DSS, SOX, HIPAA, GDPR, FISMA, NIST, and CCPA, and running enterprise risk and third-party risk programs.
How hard is CompTIA SecurityX (CAS-005)?
SecurityX is considered one of the harder vendor-neutral security certifications, and the pass/fail-only scoring makes that harder to soften psychologically — there is no partial-credit scaled score to fall back on if you have a rough section. The performance-based questions test whether you can actually configure something correctly, not just recognize the right term on a multiple-choice list.
The most common sticking point is the sheer breadth: candidates who are strong in one area (say, cloud security engineering) but weaker in another (say, governance and compliance frameworks) often underestimate how much the exam expects competence across all four domains simultaneously. Cryptography and PKI design questions and enterprise-scale architecture trade-off questions are frequently cited as the toughest material.
For someone who genuinely meets the recommended ten years of IT experience with five years hands-on in security, a realistic prep window is six to ten weeks of focused review. Candidates coming in below that experience bar should expect this exam to be considerably harder and should budget significantly more time, ideally alongside real architecture and engineering work rather than study alone.
How to prepare for CompTIA SecurityX (CAS-005): a study plan
Because SecurityX assumes real seniority, the study plan should reinforce and organize existing experience as much as it fills gaps.
- Weeks 1–2: Map your experience against all four domains. Read through the full objectives list and honestly rate your hands-on comfort in each of the four domains. Most candidates find at least one weak spot even after years of security work.
- Weeks 3–5: Go deep on your weakest domain first. Pair reading with labs — build a small PKI, configure a zero trust policy, or run through an incident response tabletop — so the concepts are anchored to something you actually did, not just read.
- Weeks 6–7: Drill performance-based scenarios. Practice questions that require you to configure or diagnose something, not just pick a definition. Read every explanation, since the reasoning behind a governance or architecture decision often matters more than the final answer.
- Final week: Full timed run-throughs. Simulate the 165-minute length, practice pacing so PBQs do not eat time meant for the multiple-choice section, and review your weakest domain one final time.
Treat practice questions as a way to stress-test judgment calls across architecture, engineering, operations, and governance simultaneously — that cross-domain reasoning, more than any single fact, is what the exam is built to measure.
CompTIA SecurityX (CAS-005) FAQ
How much does the CAS-005 exam cost?
CompTIA does not always publish exam pricing openly, and advanced-tier exams have historically cost noticeably more than Security+. Confirm the current voucher price on the official CompTIA store before purchasing.
Is CAS-005 the same as CASP+?
SecurityX is the current name and version for what was previously branded CASP+ (CompTIA Advanced Security Practitioner). CAS-005 is the exam code for the current SecurityX version, replacing the earlier CAS-004.
What score do I need to pass?
There is no numeric passing score to aim for. CAS-005 is scored pass/fail only, so your result report will simply state whether you passed rather than giving a scaled score like Security+ does.
Are there mandatory prerequisites?
There are no mandatory prerequisites enforced at registration. CompTIA recommends roughly ten years of general IT experience and five years of hands-on security experience, plus knowledge equivalent to Network+, Security+, CySA+, Cloud+, and PenTest+.
How long is the certification valid?
Three years from the date you pass, renewable through CompTIA's Continuing Education program by earning CEUs or by stacking a higher-level certification.
Is SecurityX worth pursuing over CISSP or other advanced certifications?
It depends on your career direction. SecurityX stays more hands-on and technical than management-oriented advanced certifications, which makes it a strong fit for security architects and engineering leads who want a credential that still tests configuration and design skill rather than purely policy and management knowledge.
NotJustExam