CompTIA SecurityX (CAS-005) Practice Exam
Prepare for CompTIA’s expert-level security-architect and senior-engineer exam — formerly CASP+ — across all four objective areas: governance and risk, security architecture, security engineering, and security operations. Objective-mapped questions, instant feedback in Learn mode, and a full timed simulation in Exam mode. Start with a 24-hour free trial.
Start 24-hour free trial →CompTIA SecurityX (CAS-005) exam at a glance
- Vendor
- CompTIA
- Exam code
- CAS-005
- Certification
- CompTIA SecurityX (formerly CASP+)
- Level
- Expert / security architect & senior engineer (CompTIA Xpert series)
- Blueprint
- Exam version V5, launched December 17, 2024 (current edition)
- Format
- Maximum of 90 questions; multiple-choice and performance-based
- Duration
- Maximum of 165 minutes
- Scoring
- Pass/fail only — no scaled score is reported
- Delivery
- Pearson VUE test center or OnVUE online proctored
- Recommended experience
- About 10 years of IT experience including 5 years hands-on security; Network+, Security+, CySA+, Cloud+, and PenTest+ (or equivalent) are useful groundwork
- Languages
- English (other languages to be determined)
Source: CompTIA — SecurityX (CAS-005) certification (exam details & objectives). Verify current details with CompTIA before scheduling.
About the CompTIA SecurityX (CAS-005) certification
CompTIA SecurityX is an expert-level credential in CompTIA’s Xpert series, and it is the official rebrand and update of CASP+ (the CompTIA Advanced Security Practitioner). It is aimed at the people at the top of the technical security ladder: security architects and senior security engineers who design, build, and lead an enterprise’s entire security posture across on-premises, cloud, and hybrid environments. Where Security+ proves you understand security fundamentals and CySA+ proves you can analyze threats, SecurityX proves you can architect and engineer the whole defense — and it stays deliberately hands-on, with performance-based questions that assume you have actually done the work.
SecurityX (series code CAS-005) launched in December 2024, replacing CASP+ CAS-004. It delivers up to 90 questions — a mix of multiple-choice and scenario-driven performance-based items — across four objective areas, and unlike CompTIA’s core exams it is scored on a straight pass/fail basis with no scaled number. Security engineering (31%) is the heaviest area, with Security architecture (27%) close behind. Every PowerKram practice question maps to one of the four areas, so a weak score points you at the exact objective to revisit. For context on how senior certifications fit alongside formal education, see our guide to choosing certifications over a college degree.
SecurityX (CAS-005) exam objectives and weights
CompTIA splits the V5 exam across four objective areas. The weights below are CompTIA’s own and sum to 100% — plan your study time roughly in proportion to them.
Automation and scripting (PowerShell, Bash, Python, IaC, SOAR), vulnerability management and SCAP, advanced cryptography (post-quantum, homomorphic encryption, forward secrecy), and cryptographic use cases and techniques including tokenization, code signing, and certificate-based authentication.
Cloud capabilities and data security (CASB, shared responsibility, container and serverless security), cloud control strategies, network architecture and segmentation, security boundaries, deperimeterization (SASE, SD-WAN, SDN), and Zero Trust design.
Monitoring and data analysis (SIEM, correlation, behavior baselines), vulnerabilities and attack surface with mitigations, threat hunting and threat intelligence (OSINT, ISACs, STIX/TAXII, Sigma/YARA), and incident response including malware analysis and root cause analysis.
Security program documentation and management, frameworks (COBIT, ITIL, NIST, CSF), configuration management, GRC tooling, data governance, risk management and third-party risk, threat modeling (ATT&CK, CAPEC, STRIDE), and compliance with standards such as PCI DSS and ISO/IEC 27000.
Who the SecurityX exam is for
SecurityX is built for senior technical security professionals: security architects, senior security engineers, and technical security leads responsible for designing and running an enterprise’s defenses. CompTIA frames it as an expert credential — it expects roughly ten years of IT experience including about five years hands-on in security, with Network+, Security+, CySA+, Cloud+, and PenTest+ (or equivalent knowledge) as useful groundwork rather than formal prerequisites. This is not an entry point; it is where an experienced practitioner proves architect- and engineer-level mastery. It also maps to several NICE and DoD 8140 work roles, including security architect and security control assessor.
If you are still building toward that level, our Security+ practice exam and CySA+ practice exam cover the foundational and analyst-level security skills SecurityX assumes. For where senior security work leads in salary and scope, the Cybersecurity Specialist career guide in our career hub maps the path toward architect and engineering-lead roles.
What this SecurityX practice exam delivers
Score by objective area
Every question is tagged to one of the four V5 areas, so your report shows whether Security engineering or Security architecture — the two heaviest — is dragging your readiness, not just an overall result on this pass/fail exam.
Learn mode
Immediate feedback after each question with a full explanation of why the right answer is right and why the others are wrong — built for the design-and-engineering judgment SecurityX tests.
Exam mode
A timed simulation that mirrors the demanding 165-minute format and its mix of multiple-choice and hands-on performance-based questions, so the pacing of a long expert exam feels familiar.
No setup, no download
Runs in the browser with nothing to install. Your 24-hour trial unlocks the full bank and both modes — no credit card required.
Sample SecurityX practice questions
Ten free questions spanning the four objective areas at the senior architect/engineer level the exam expects, each with a full explanation. The complete bank is available with the 24-hour trial.
An enterprise must protect sensitive customer data held in its cloud environment from unauthorized access. Which control is most effective?
- Strong encryption for data at rest and in transit, with managed keys
- Increase monitor resolution
- Install more printers
- Change the company logo
Show answer & explanation
Correct: A — encrypt at rest and in transit with proper key management. Encryption renders data unreadable to anyone without the keys, protecting it both where it is stored and as it moves; sound key management is what makes that protection hold. This is a core SecurityX cryptographic use case.
Why not the others: monitor resolution (B), printers (C), and a logo change (D) have no bearing on data confidentiality.
Source: CompTIA SecurityX objectives — Cryptographic use cases →A security architect must ensure only authorized users can reach critical applications regardless of where they connect from. Which approach best meets this?
- Multi-factor authentication within a Zero Trust access model
- Change screen brightness
- Add bandwidth
- Update printer drivers
Show answer & explanation
Correct: A — MFA within a Zero Trust model. Verifying identity with multiple factors and enforcing per-request access regardless of network location is the Zero Trust pattern SecurityX expects an architect to apply for location-independent, identity-driven access.
Why not the others: screen brightness (B), bandwidth (C), and printer drivers (D) are unrelated to access control.
Source: CompTIA SecurityX objectives — Zero Trust concepts → Further reading: PowerKram — security practices guide →An organization needs to detect and respond to advanced persistent threats (APTs) on its endpoints. Which capability is most suitable?
- Endpoint detection and response (EDR)
- Install a new phone system
- Increase RAM
- Update the employee handbook
Show answer & explanation
Correct: A — EDR. Endpoint detection and response continuously monitors endpoint behavior, detects the stealthy activity typical of APTs, and supports investigation and containment — the right tool for advanced, persistent threats.
Why not the others: a phone system (B), more RAM (C), and a handbook update (D) do not detect or respond to endpoint threats.
Source: CompTIA SecurityX objectives — Monitoring & incident response →A business must comply with regulations requiring detailed tracking of all access to confidential information. Which control should be implemented?
- Comprehensive audit logging
- Install more displays
- Change password hints
- Add more USB ports
Show answer & explanation
Correct: A — comprehensive audit logging. Detailed, tamper-resistant audit logs record who accessed what and when, providing the evidence trail regulations and compliance frameworks require for confidential-data access.
Why not the others: more displays (B), password hints (C), and USB ports (D) do nothing to satisfy a regulatory tracking requirement.
Source: CompTIA SecurityX objectives — Compliance strategies → Further reading: PowerKram — security practices guide →A security analyst discovers unauthorized devices on the corporate network. What is the most effective control to prevent this?
- Network access control (NAC)
- Increase email attachment limits
- Change desktop wallpaper
- Reboot the file server
Show answer & explanation
Correct: A — NAC. Network access control checks device identity and posture before granting access, so only authorized, compliant devices can join the network — preventing rogue devices by design.
Why not the others: attachment limits (B), wallpaper (C), and rebooting a server (D) do not control which devices can connect.
Source: CompTIA SecurityX objectives — Network architecture & boundaries →A team must ensure the integrity of critical system files and detect any unauthorized changes. Which solution is best?
- File integrity monitoring (FIM)
- Update the company logo
- Install more modems
- Change the printer ink
Show answer & explanation
Correct: A — file integrity monitoring. FIM baselines critical files (often via hashing) and alerts on unauthorized modification, giving the integrity assurance and change detection the requirement describes.
Why not the others: a logo (B), modems (C), and printer ink (D) are irrelevant to file integrity.
Source: CompTIA SecurityX objectives — Cryptographic techniques (hashing/integrity) → Further reading: PowerKram — security practices guide →A company wants to prevent employees from copying sensitive files to unauthorized USB devices. Which control should be deployed?
- Data loss prevention (DLP)
- Increase monitor size
- Change the office lighting
- Change the company logo
Show answer & explanation
Correct: A — DLP. Data loss prevention controls inspect and block sensitive data from leaving via removable media and other channels, directly addressing exfiltration to unauthorized USB devices.
Why not the others: monitor size (B), lighting (C), and a logo (D) have no effect on data movement.
Source: CompTIA SecurityX objectives — Mitigations & data protection →A business must ensure that only authorized third-party vendors can access sensitive internal systems remotely. Which approach is most secure?
- A VPN with vendor-specific credentials and least-privilege access
- Share one set of credentials among all vendors
- Allow open remote access
- Disable all remote access entirely
Show answer & explanation
Correct: A — VPN with vendor-specific credentials. Giving each vendor its own authenticated, least-privilege remote path (ideally with MFA and scoped access) lets the business grant and audit access per vendor — the secure way to enable authorized third-party remote access.
Why not the others: shared credentials (B) destroy accountability and least privilege; open access (C) is insecure; disabling all remote access (D) blocks the legitimate business need rather than securing it.
Source: CompTIA SecurityX objectives — Secure access & third-party risk → Further reading: PowerKram — security practices guide →A security team must quickly contain malware detected across multiple endpoints. Which immediate action should be taken?
- Isolate the affected devices from the network
- Increase screen brightness
- Change the company logo
- Send a company-wide email
Show answer & explanation
Correct: A — isolate (contain) the affected devices. Containment is the first incident-response priority for spreading malware: removing the infected endpoints from the network stops lateral movement while eradication and recovery proceed.
Why not the others: brightness (B) and a logo (C) are irrelevant; a company-wide email (D) may be part of communication later but does not contain the malware.
Source: CompTIA SecurityX objectives — Incident response →A company wants to verify that its security policies are being followed consistently across global offices. What is the best way to achieve this?
- Conduct regular security audits and compliance assessments
- Increase the printer budget
- Change the desktop icons
- Update the office color scheme
Show answer & explanation
Correct: A — regular audits and compliance assessments. Periodic audits and assessments measure whether policies are actually being followed and surface gaps for remediation — the governance mechanism for enforcing consistent policy across an enterprise.
Why not the others: printer budget (B), desktop icons (C), and a color scheme (D) are unrelated to policy enforcement.
Source: CompTIA SecurityX objectives — Governance & audits →Keep going: study guides and career paths
SecurityX proves you can architect and engineer an enterprise’s entire security posture — the top of CompTIA’s cybersecurity path. Two PowerKram hubs back this exam up.
Deep dive: SecurityX exam structure, scoring, the CASP+ rebrand & study path
Exam structure and how it’s scored
SecurityX (CAS-005) delivers a maximum of 90 questions in up to 165 minutes — a long sitting that reflects its expert level — combining multiple-choice items with demanding performance-based questions that drop you into a simulated design, engineering, or response task. Unlike CompTIA’s core exams, it is scored strictly pass/fail, with no scaled number reported. Performance-based items are time-consuming and tend to appear early, so disciplined pacing across the long window matters more here than on a 90-minute exam. See our security architecture & engineering guides →
The CASP+ rebrand
SecurityX is the rebrand and update of CASP+ (CompTIA Advanced Security Practitioner). CompTIA moved the certification into its expert-tier Xpert series in December 2024, releasing CAS-005 to replace CASP+ CAS-004; the older exam retired June 17, 2025. The change did not affect existing CASP+ holders, who automatically received the SecurityX badge. The objective set was streamlined (from 28 to 23 objectives) and modernized with AI threat modeling, post-quantum cryptography, deeper Zero Trust and SASE, compliance-as-code, and a cloud-native emphasis. If you studied CASP+ CAS-004, expect a real content gap before sitting CAS-005. CompTIA’s official SecurityX page →
Where the weight sits and how to study
Security engineering (31%) and Security architecture (27%) together make up well over half the exam, with Security operations (22%) and Governance, risk, and compliance (20%) close behind. Because the exam rewards hands-on judgment, reading alone will not carry you: build and harden a reference architecture, implement Zero Trust and PKI, automate with IaC and SOAR, and practise interpreting SIEM and threat-hunting output. PowerKram’s objective-level scoring surfaces which of the four is weakest in your first practice run. Read the security practices guide →
Recommended experience and prerequisites
SecurityX has no hard prerequisite, but it is genuinely an expert credential: CompTIA frames it for candidates with around ten years of IT experience including five years hands-on in security. Network+, Security+, CySA+, Cloud+, and PenTest+ (or equivalent knowledge) form a sensible foundation beneath it. The exam is delivered through Pearson VUE at a test center or online with a proctor via OnVUE; the online option needs a quiet, private room and a webcam system check. Fees and policies vary by region and change over time, so confirm the current voucher price on CompTIA’s site before you book. For role-by-role context on where these senior paths lead, browse our Career Hub. Cybersecurity Specialist role guide →
Where SecurityX sits in the CompTIA path
SecurityX is part of CompTIA’s expert-tier Xpert series, sitting at the top of the cybersecurity pathway above the foundational and analyst-level certifications. A common route is to build through Security+ for fundamentals and CySA+ for analysis, accumulate years of hands-on architecture and engineering experience, and then target SecurityX to validate senior technical capability. It sits alongside CompTIA’s other Xpert-tier credentials such as the network-architect exam. CloudNetX (expert network architect) practice exam →
Start your free 24-hour SecurityX practice trial
Full access to the question bank, both study modes, and objective-level scoring. No credit card required.
Start free trial →