SecurityX (CAS-005): The Complete Guide
SecurityX is CompTIA's expert-level cybersecurity certification — the credential for practitioners who architect, engineer, and defend complex enterprise environments rather than just administer them. If you're weighing whether to sit CAS-005, this guide gathers the current exam facts, explains what each domain expects, and points you toward focused resources for the parts that matter most. The linked articles go deeper; this is the map.
If the name is new to you, here's the key context up front: SecurityX is the rebranded, updated successor to CASP+ (CompTIA Advanced Security Practitioner), and it sits in CompTIA's Xpert Series alongside credentials like DataX and CloudNetX. It targets senior technical staff, not managers.
What SecurityX validates
The certification confirms you can operate at the top of the technical security stack. In practice, a successful candidate can:
- Architect, engineer, integrate, and implement secure solutions across complex, hybrid environments to support a resilient enterprise.
- Use automation, monitoring, detection, and incident response to proactively support ongoing security operations.
- Apply cryptographic technologies appropriately, including an understanding of emerging trends such as AI and post-quantum cryptography.
- Use governance, compliance, risk-management, and threat-modeling strategies throughout the security lifecycle.
This is deliberately senior work. Where a foundational cert asks whether you know a control, SecurityX asks whether you can design it, integrate it into a messy real-world environment, and justify the trade-offs.
The current exam at a glance
The version in the field now is CAS-005, marketed as V5. It replaced CAS-004, the final CASP+ exam, which retired on June 17, 2025.
| Item | Detail |
|---|---|
| Exam code | CAS-005 (V5) |
| Number of questions | Up to 90 |
| Question types | Multiple-choice, multiple-select, and performance-based (PBQs) |
| Length | 165 minutes |
| Scoring | Pass/fail only — no scaled score |
| Recommended experience | 10+ years of general IT experience, including at least 5 years of hands-on security |
| Accreditation | ANSI / ISO 17024 |
| Validity | 3 years, renewable via continuing education |
One detail catches people off guard: SecurityX is pass/fail with no numeric score. You won't see a 750-style figure — just a pass or fail result. We unpack what that means for your strategy in the exam format guide.
The four domains and their weights
CAS-005 is organized into four domains. The weights tell you where to concentrate.
- Governance, Risk, and Compliance — 20%. Risk strategies, vendor risk, compliance frameworks, and threat modeling.
- Security Architecture — 27%. Designing secure network, system, data-flow, and access architectures across cloud, on-prem, and hybrid, with zero trust and SASE as core concepts.
- Security Engineering — 31%. The largest domain: implementing and hardening controls, cryptography (including post-quantum), secure DevOps, and automation.
- Security Operations — 22%. Monitoring, detection, incident response, threat hunting, and analysis.
We break all four down objective by objective in the SecurityX domains guide.
Experience and prerequisites
There's no mandatory prerequisite certification — you can register and sit SecurityX directly. But this isn't an entry point. CompTIA recommends roughly 10 years of general IT experience with at least 5 in hands-on security, and the exam is built for people who've actually run enterprise security programs. If you're earlier in your journey, Security+ and a role like CySA+ or PenTest+ are more appropriate stepping stones first.
Wondering how it compares to the other big advanced credential? Our piece on SecurityX vs CISSP lays out where each one fits.
Coming from CASP+?
If you already know CASP+, you'll recognize a lot — but CAS-005 isn't just a rename. CompTIA consolidated the objectives (from 28 down to 23) and added modern content: AI threat modeling, post-quantum cryptography, zero trust and SASE as core architecture, compliance-as-code, and a cloud-native, hybrid default. Our CASP+ to SecurityX guide covers exactly what's new so you don't over-study familiar ground or under-study the additions.
How to prepare
SecurityX rewards depth and hands-on fluency. A realistic plan blends structured content, hands-on labs, and question practice — because a large share of the objectives are scenario-based and the PBQs are hands-on simulations you can't memorize your way through.
- Follow a structured schedule. See the SecurityX study plan.
- Build hands-on reps. The PBQ and hands-on prep guide covers the labs and skills worth rehearsing.
- Pick materials deliberately. Our study resources overview compares CertMaster Study, Perform, Labs, and Practice.
Careers and recognition
SecurityX maps to senior technical roles: security architect, lead security engineer, senior incident-response or blue-team lead, and principal security positions. It's ANSI-accredited and appears in workforce frameworks that some employers and public-sector roles reference. As an expert-tier CompTIA credential, earning it also renews eligible lower-level CompTIA certifications you hold under the stackable model.
Keeping it current
SecurityX is valid for three years and renews through CompTIA's continuing education program — continuing education units, or passing the newest version of the exam. Because it sits near the top of the pathway, it's often the credential that renews everything beneath it.
Getting started
For most candidates, an integrated environment that combines learning content with hands-on labs is the most efficient backbone.
Start here: CompTIA CertMaster Perform for SecurityX (CAS-005) brings learning and labs together. When you're ready to book the exam, an official voucher is here. As an Authorized CompTIA Partner, we carry official materials only.
A note on voucher eligibility: Voucher eligibility depends on your exam testing location, per CompTIA policy. Testing in an emerging-market region? We don't sell those here — contact us.
FAQ
Is SecurityX the same as CASP+? Yes. SecurityX is the rebranded, updated version of CASP+. CAS-005 replaced the final CASP+ exam, CAS-004, which retired on June 17, 2025.
What score do I need to pass? There's no numeric score. SecurityX is pass/fail only, and CompTIA doesn't publish the threshold.
How many questions and how long? Up to 90 questions in 165 minutes, mixing multiple-choice, multiple-select, and performance-based questions.
Do I need a certification before SecurityX? No prerequisite is enforced, but it's an expert-level exam. CompTIA recommends around 10 years of IT experience with at least 5 in security.
Is my old CASP+ badge still valid? Existing CASP+ holders had their credential recognized as SecurityX without re-testing. Check your CompTIA account for specifics.
How long is the certification valid? Three years, renewable through continuing education units or by passing the current exam version.
0 comments