CompTIA SecurityX Exam CAS-005

Course code: COMPCAS04

SecurityX is an advanced cybersecurity certification designed for security architects and senior security engineers. It demonstrates that you have the skills needed to design, build, and implement secure solutions across complex environments. It also proves that you can support a resilient enterprise while addressing governance, risk, and compliance requirements.

Professional
and certified lecturers

Internationally
recognized certifications

Wide range of technical
and soft skills courses

Great customer
service

Making courses
exactly to measure your needs

Exam dates

Starting date: Upon request

Type: Exam

Course duration: 2h 45min

Language: en

Price without VAT: 400 EUR

Register

Starting date: Upon request

Type: Exam + Retake

Course duration: 2h 45min

Language: en

Price without VAT: 522 EUR

Register

Starting
date
Place
Type Course
duration
Language Price without VAT
Upon request Exam 2h 45min en 400 EUR Register
Upon request Exam + Retake 2h 45min en 522 EUR Register
G Guaranteed course

Didn't find a suitable date?

Write to us about listing an alternative tailor-made date.

Contact

Course structure

Governance, risk, and compliance (20%)

  • Security program documentation: policies, procedures, standards, and guidelines.
  • Program management: training (phishing, security, privacy), communication, reporting, and RACI matrix.
  • Frameworks: COBIT, ITIL, etc.
  • Configuration management: asset life cycle, CMDB, and inventory.
  • GRC tools: mapping, automation, and compliance tracking.
  • Data governance: production, development, testing, and QA.
  • Risk management: impact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability.
  • Threat modeling: actor characteristics, attack patterns, and frameworks (ATT&CK, CAPEC, STRIDE).
  • Attack surface: architecture reviews, data flows, and trust boundaries.
  • Compliance strategies: industry-specific standards (PCI DSS, ISO/IEC 27000).
  • Security frameworks: NIST, CSF, CSA, and others.

Security architecture (27%)

  • Cloud capabilities: CASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads.
  • Cloud data security: data exposure, leakage, remanence, insecure storage, and encryption keys.
  • Cloud control strategies: proactive, detective, and preventative controls; customer-to-cloud connectivity, service integration, and continuous authorization.
  • Network architecture: segmentation, microsegmentation, VPN, always-on VPN, and API integration.
  • Security boundaries: asset identification, management, attestation, data perimeters, and secure zones.
  • Deperimeterization: SASE, SD-WAN, and software-defined networking.
  • Zero trust concepts: defining subject-object relationships.

Security engineering (31%)

  • Automation: scripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation.
  • Vulnerability management: scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS).
  • Advanced cryptography: PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration.
  • Cryptographic use cases: data at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication.
  • Cryptographic techniques: tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography.

Security operations (22%)

  • Monitoring and data analysis: SIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users).
  • Vulnerabilities and attack surface: injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth.
  • Threat hunting:  internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort).
  • Incident response: malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis.

Certification

Exam Codes CAS-005
Launch Date December 17, 2024
Exam Description SecurityX covers the technical knowledge and skills required to architect, engineer, integrate, and implement secure solutions across complex environments to support a resilient enterprise while considering the impact of governance, risk, and compliance requirements.
Number of Questions Maximum of 90 questions
Type of Questions Multiple-choice and performance-based
Length of Test 165 Minutes
Passing Score This test has no scaled score; it’s pass/fail only.
Recommended Experience Minimum of 10 years of general hands-on IT experience, including 5 years of hands-on security, with Network+, Security+, CySA+, Cloud+, and PenTest+ or equivalent knowledge
Languages  English
Retirement Usually three years after launch

Renewal

Keep your certification up to date with CompTIA’s Continuing Education (CE) program. It’s designed to be a continued validation of your expertise and a tool to expand your skillset. It’s also the ace up your sleeve when you’re ready to take the next step in your career.

Get the most out of your certification
Information technology is an incredibly dynamic field, creating new opportunities and challenges every day. Participating in our Continuing Education program will enable you to stay current with new and evolving technologies, and remain a sought-after IT and security expert.

ComGate payment gateway MasterCard Logo Visa logo