CompTIA SecurityX Exam CAS-005

Course code: COMPCAS04

SecurityX is an advanced cybersecurity certification designed for security architects and senior security engineers. It demonstrates that you have the skills needed to design, build, and implement secure solutions across complex environments. It also proves that you can support a resilient enterprise while addressing governance, risk, and compliance requirements.

Professional
and certified lecturers

Internationally
recognized certifications

Wide range of technical
and soft skills courses

Great customer
service

Making courses
exactly to measure your needs

Exam dates

Starting date: Upon request

Type: Exam

Course duration: 2h 45min

Language: en

Price without VAT: 458 EUR

Register

Starting
date
Place
Type Course
duration
Language Price without VAT
Upon request Exam 2h 45min en 458 EUR Register
G Guaranteed course

Didn't find a suitable date?

Write to us about listing an alternative tailor-made date.

Contact

Course structure

Governance, risk, and compliance (20%)

  • Security program documentationpolicies, procedures, standards, and guidelines.
  • Program managementtraining (phishing, security, privacy), communication, reporting, and RACI matrix.
  • FrameworksCOBIT, ITIL, etc.
  • Configuration managementasset life cycle, CMDB, and inventory.
  • GRC tools: mapping, automation, and compliance tracking.
  • Data governanceproduction, development, testing, and QA.
  • Risk managementimpact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability.
  • Threat modelingactor characteristics, attack patterns, and frameworks (ATT&CK, CAPEC, STRIDE).
  • Attack surfacearchitecture reviews, data flows, and trust boundaries.
  • Compliance strategies: industry-specific standards (PCI DSS, ISO/IEC 27000).
  • Security frameworks: NIST, CSF, CSA, and others.

Security architecture (27%)

  • Cloud capabilitiesCASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads.
  • Cloud data securitydata exposure, leakage, remanence, insecure storage, and encryption keys.
  • Cloud control strategiesproactive, detective, and preventative controls; customer-to-cloud connectivity, service integration, and continuous authorization.
  • Network architecturesegmentation, microsegmentation, VPN, always-on VPN, and API integration.
  • Security boundariesasset identification, management, attestation, data perimeters, and secure zones.
  • DeperimeterizationSASE, SD-WAN, and software-defined networking.
  • Zero trust conceptsdefining subject-object relationships.

Security engineering (31%)

  • Automationscripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation.
  • Vulnerability management: scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS).
  • Advanced cryptographyPQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration.
  • Cryptographic use casesdata at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication.
  • Cryptographic techniquestokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography.

Security operations (22%)

  • Monitoring and data analysisSIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users).
  • Vulnerabilities and attack surface: injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth.
  • Threat hunting:  internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort).
  • Incident response: malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis.

Certification

Exam Codes CAS-005
Launch Date December 17, 2024
Exam Description SecurityX covers the technical knowledge and skills required to architect, engineer, integrate, and implement secure solutions across complex environments to support a resilient enterprise while considering the impact of governance, risk, and compliance requirements.
Number of Questions Maximum of 90 questions
Type of Questions Multiple-choice and performance-based
Length of Test 165 Minutes
Passing Score This test has no scaled score; it’s pass/fail only.
Recommended Experience Minimum of 10 years of general hands-on IT experience, including 5 years of hands-on security, with Network+, Security+, CySA+, Cloud+, and PenTest+ or equivalent knowledge
Languages  English
Retirement Usually three years after launch

Renewal

Keep your certification up to date with CompTIA’s Continuing Education (CE) program. It’s designed to be a continued validation of your expertise and a tool to expand your skillset. It’s also the ace up your sleeve when you’re ready to take the next step in your career.

Get the most out of your certification
Information technology is an incredibly dynamic field, creating new opportunities and challenges every day. Participating in our Continuing Education program will enable you to stay current with new and evolving technologies, and remain a sought-after IT and security expert.

ComGate payment gateway MasterCard Logo Visa logo