Free Practice Questions for SecurityX
Exam-style questions and explanations by OpenExamPrep.
Loading practice questions...
Explore More CompTIA Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.
Key Facts: SecurityX Exam
Dec 2024
Launch Date
Replaced CASP+ (CAS-004)
CAS-005
Exam Code
CompTIA
Pass/Fail
Scoring
CompTIA (no scaled score)
165 min
Exam Duration
CompTIA
$525
Exam Fee
CompTIA (USD)
3 years
Certification Validity
CompTIA CE program
CompTIA SecurityX (CAS-005) launched December 2024 as the replacement for CASP+. It covers four domains: Governance/Risk/Compliance (~20%), Security Architecture (~30%), Security Engineering (~25%), and Security Operations (~25%). The exam has approximately 90 multiple-choice and performance-based questions in 165 minutes with pass/fail scoring. Exam fee is $525. Recommended experience: 10+ years IT with 5+ years in security.
Sample SecurityX Practice Questions
Try these sample questions to review concepts for the SecurityX exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 297+ question experience with AI tutoring.
1A security architect is designing a zero-trust architecture for a hybrid enterprise environment. The organization needs to enforce least-privilege access for privileged accounts accessing both on-premises and cloud workloads. Which combination of controls BEST supports continuous verification in this scenario?
2An organization is implementing post-quantum cryptography (PQC) to protect long-lived secrets. NIST has finalized several PQC standards. Which algorithm is the PRIMARY NIST-standardized choice for key encapsulation mechanisms (KEM) resistant to quantum attacks?
3A threat hunter discovers anomalous outbound connections from a bastion host that correlate with MITRE ATT&CK technique T1572 (Protocol Tunneling). The traffic appears to be DNS queries with unusually large TXT record responses. Which BEST describes the threat and the most effective detection control?
4An enterprise CISO must align security investments with the NIST Cybersecurity Framework (CSF) 2.0. The board requests a metric demonstrating resilience improvement. Which metric BEST maps to the CSF 2.0 'Recover' function and would be most meaningful to board-level stakeholders?
5A DevSecOps team is embedding security into a CI/CD pipeline for a containerized microservices application. To prevent supply chain attacks, which control provides the MOST comprehensive protection against malicious code introduced through third-party dependencies?
6A SOC analyst is investigating a potential lateral movement event. eBPF-based telemetry shows a process on a Linux host making unexpected syscalls: ptrace() on a remote process followed by mmap() with PROT_EXEC. Which MITRE ATT&CK technique does this MOST likely indicate, and what is the appropriate containment action?
7An organization is deploying a SOAR platform to automate incident response. A playbook must handle a phishing alert that may involve credential harvesting. Which automated action sequence is MOST appropriate while preserving human oversight for high-risk decisions?
8During a third-party risk assessment, a critical SaaS vendor cannot provide SOC 2 Type II reports and instead offers self-attestation questionnaires. The vendor processes PII covered by GDPR. Which risk treatment is MOST appropriate?
9A network engineer must secure BGP peering sessions between autonomous systems to prevent route hijacking. Which combination of controls provides the MOST comprehensive defense against both BGP prefix hijacking and path manipulation attacks?
10An organization's OAuth 2.0 implementation allows third-party applications to request the 'openid profile email' scope. A security review finds that refresh tokens are stored in browser localStorage and the authorization server does not enforce token binding. Which attack is MOST feasible and what is the MOST effective mitigation?
About the SecurityX Exam
CompTIA SecurityX (CAS-005) is the expert-level security certification that replaced CASP+ in December 2024. It validates the advanced skills needed to architect, engineer, integrate, and implement secure solutions across complex enterprise environments. SecurityX is approved for DoD 8140 IASAE Level III and IAM Level III roles and is designed for senior security practitioners with 10+ years of experience.
Exam sponsor: Pearson VUE. The requirements and fees below concern the certification or admission exam, separate from our free practice resources.
Questions
90 questions
Time Limit
165 minutes
Passing Score
Pass/Fail
Reported exam pass rate: Not published. CompTIA does not publish official exam-level pass rates. Exam sponsor website
Fees, eligibility, and exam policies can change. Confirm them with the exam sponsor before applying or paying.
Our practice resources: topics covered
We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.
Governance, Risk, and Compliance
Risk quantification (FAIR), regulatory frameworks (GDPR, CCPA, PCI DSS, HIPAA), data classification, security policy, third-party risk, and tabletop exercises
Security Architecture
Zero-trust architecture, cloud security design (CSPM, CASB, SASE), PKI design, network micro-segmentation, hypervisor security, disaster recovery (RTO/RPO), and BCP
Security Engineering
Advanced cryptography, DevSecOps, CI/CD pipeline security, SBOM, supply chain integrity, endpoint protection (TPM, Secure Boot, FDE), IAM, SAML, OAuth 2.0, and API security
Security Operations
Threat hunting, MITRE ATT&CK mapping, SIEM/SOAR automation, EDR behavioral analytics, digital forensics (memory analysis, chain of custody), incident response, and threat intelligence
Preparing for the SecurityX Exam
What You Need to Know
- Passing score: Pass/Fail
- Exam length: 90 questions
- Time limit: 165 minutes
- Exam / certification fees: $525 Official sources
Using Our Practice Resources
- Work through all 297 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
SecurityX: Suggested Study Strategy
Frequently Asked Questions
What is CompTIA SecurityX and how does it relate to CASP+?
CompTIA SecurityX (CAS-005) replaced CompTIA CASP+ in December 2024. It is CompTIA's expert-level cybersecurity certification validating advanced skills in security architecture, engineering, governance, and operations. The exam code changed from CAS-004 (CASP+) to CAS-005 (SecurityX). Active CASP+ certifications remain valid through their 3-year cycle.
What is the SecurityX CAS-005 exam format?
SecurityX CAS-005 has approximately 90 questions (multiple choice and performance-based) in 165 minutes. Scoring is pass/fail with no published scaled score. The exam fee is $525 USD. It is administered by Pearson VUE at test centers and online via OnVUE.
What experience do I need for SecurityX?
CompTIA recommends 10+ years of IT administration experience including 5+ years of hands-on technical security experience. Most candidates have Security+, CySA+, or CASP+ and work in senior security roles (security architect, security engineer, senior security analyst). No prerequisite certification is formally required to register.
What are the four SecurityX CAS-005 domains?
CAS-005 covers: Security Architecture (~30%) — zero-trust, cloud design, PKI, micro-segmentation, BCP; Security Engineering (~25%) — cryptography, DevSecOps, SBOM, endpoint security, IAM; Security Operations (~25%) — threat hunting, MITRE ATT&CK, SOAR, forensics, incident response; Governance, Risk, and Compliance (~20%) — FAIR, NIST CSF, regulatory compliance, third-party risk.
Is SecurityX CAS-005 approved for DoD roles?
Yes. CompTIA SecurityX is approved under DoD Directive 8140 for IASAE Level III and IAM Level III positions. It is the expert-level DoD-approved certification for senior security architects and engineers in government and defense contractor environments.
How long should I study for SecurityX?
Most candidates with senior security experience need 200-300 hours over 6-12 months. Focus on Security Architecture (30%) and Security Operations (25%) first. Use MITRE ATT&CK Navigator, practice FAIR risk quantification, study NIST SP 800-53 control families, and complete full-length performance-based practice scenarios.