CompTIA
Free CompTIA SecurityX Practice Questions
The CompTIA SecurityX exam is up to 90 questions in 165 minutes, and the voucher costs $499. CertCrush provides 400 syllabus-aligned practice questions and 20 performance-based questions across all 4 exam domains, each with a full explanation. Free to try, no account required.
SecurityX (CAS-005) is CompTIA's expert-level security certification and the exam that CASP+ became. It covers governance and risk, security architecture, security engineering and security operations for practitioners who design and build controls rather than monitor them.
Practice content last updated · Independently written and aligned to CompTIA’s published exam objectives.
10
Sample questions
165 min
Exam time limit
70%
Practice pass mark
$499
Exam voucher
About the CompTIA SecurityX Exam
CompTIA SecurityX carries the exam code CAS-005 and replaces CASP+. The blueprint changed along with the name. Four domains split the exam: governance, risk and compliance at 20 percent, security architecture at 27 percent, security engineering at 31 percent, and security operations at 22 percent. Well over half of it therefore sits in architecture and engineering, which is where candidates arriving from Security+ or CySA+ lose most of their marks. Those two domains ask you to choose a design and defend it against constraints such as legacy systems that cannot be patched, regulatory scope, a merger that has to be integrated, and a fixed budget. Recalling what a control does will not answer them. The exam runs up to 90 questions in 165 minutes and mixes multiple-choice items with performance-based tasks. CompTIA reports it as pass or fail with no scaled score, so there is no published number to aim at. Treat every domain as one you have to be competent in rather than one you can average away. SecurityX is written for people already doing the work: security architects, senior engineers, technical leads and consultants who own designs rather than tickets. CompTIA keeps it a practitioner credential rather than a management one, so the questions stay technical even inside the governance domain, where you are asked how a control satisfies a requirement and what evidence would prove it. This course follows the CAS-005 objectives domain by domain, with practice questions, flashcards and performance-based tasks weighted the way the real exam is.
Exam Domains Covered
Exam Format & Details
Up to 90 questions in 165 minutes, mixing multiple-choice items with performance-based tasks. CompTIA reports the result as pass or fail and publishes no scaled passing score for CAS-005. The CompTIA Store lists the individual voucher at USD 499. Booked through Pearson VUE, at a test centre or online.
Why Practice Questions Matter
SecurityX questions are long. One item can run a full paragraph of context before it asks anything, and all four answers are often defensible controls with a single one that fits the constraint buried in the scenario. What you practise here is finding that constraint before you read the options, which is a reading habit rather than a recall drill. Several hundred questions in this format teach you to spot the sentence that decides the answer, and every explanation says why the near-miss option fails, because that distinction is what the exam actually tests.
Try CompTIA SecurityX
Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.
Get full access to CompTIA SecurityX
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
This course
$9.99
one-time
Monthly
$12.99
per month · all courses
Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in
Try 2 performance tasks free
Drag-and-drop, sequencing and configuration tasks that mirror the interactive questions on the real CompTIA SecurityX exam — marked with partial credit.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CompTIA SecurityX exam — not actual exam content.
Q1.A newly appointed CISO at a 900-person manufacturer finds that every disagreement about a security decision resolves in favour of whichever director argues hardest. There is a signed acceptable use policy and a draft multi-factor authentication standard, but no agreement on what the security function may decide by itself and what it may only recommend. Which document addresses the root problem?
- A.A charter establishing the security function, its reporting line, and the decisions it can make unilaterally versus recommend.
- B.An expanded acceptable use policy that lists disciplinary consequences for non-compliance.
- C.A RACI matrix covering the current multi-factor authentication rollout.
- D.An approved multi-factor authentication standard that engineering must implement.
Domain: Governance, Risk, and Compliance
Q2.A regulator examining a payments platform asks for evidence that multi-factor authentication is enforced on every system processing cardholder data. The security team sends the board-approved access control policy and the Statement of Applicability row marking the control as applicable. The regulator repeats the request unchanged. Which two items answer the question actually asked? Select two.
- A.An export of the identity provider's conditional access configuration for the in-scope systems, together with the current approved exclusion list.
- B.Signed quarterly access review records showing who reviewed which accounts and what was remediated.
- C.A memo from the CISO confirming that the access control policy is mandatory for all staff.
- D.The vendor datasheet for the authenticator product currently deployed.
- E.A steering committee minute recording approval of the access control policy.
Domain: Governance, Risk, and Compliance
Q3.A board has signed a one-page risk appetite statement whose strongest line reads: "We have a low appetite for cyber risk." At a design review for a new claims portal, the architect cannot use any line in the statement to settle whether a proposed shared administrative account is inside or outside appetite. The chief risk officer wants the statement fixed before the next board cycle. What should the architect propose?
- A.Map the appetite statement onto framework implementation tiers so the board can track a single maturity score each quarter.
- B.Attach a five by five heat map so the board can see which current risks fall outside appetite.
- C.Obtain a fresh board signature on the existing wording so the statement has a documented owner and date.
- D.Rewrite each line so it yields a number, a boundary or a named approver, and test that an architect can derive at least one design decision from every line before it returns to the board.
Domain: Governance, Risk, and Compliance
Q4.A member services platform falls under an appetite statement that accepts up to four hours of recovery time and up to fifteen minutes of data loss. The disaster recovery budget is fixed and will not stretch to a second live production footprint. Which design satisfies the stated constraints?
- A.Nightly offsite backups with a documented six-hour restore commitment from the recovery vendor.
- B.Near-continuous replication to a warm secondary, with a documented and rehearsed failover schedule.
- C.Hourly snapshot shipping to a standby region, with restores rehearsed twice a year.
- D.Active-active deployment across two regions with automatic traffic steering.
Domain: Governance, Risk, and Compliance
Q5.An operations team has configured its paging rule for a customer-facing outage to fire at four hours, matching the figure in the approved risk appetite statement exactly. The service owner argues that alerting any earlier would generate noise. What should the security architect advise?
- A.Set escalation at three hours so the tolerance band leaves room to react before the appetite figure is breached.
- B.Keep the four-hour trigger and rely on the post-incident review to catch repeated near-breaches.
- C.Ask the board to widen appetite to six hours so the four-hour alert becomes an early warning.
- D.Replace the time-based alert with a severity-based one raised by the on-call engineer's judgement.
Domain: Governance, Risk, and Compliance
Q6.A retailer plans to deploy camera analytics across all stores to infer shopper age bracket and dwell time, and to match repeat visitors across locations using facial vectors. The programme lead wants to know what has to happen before development starts. What is the correct first step?
- A.Complete a data protection impact assessment before processing begins, and let its findings shape the design
- B.Post clear signage and update the privacy notice, then proceed with the deployment
- C.Collect consent at the store entrance through a scannable code before enabling the cameras
- D.Deploy in a single pilot store, then assess the privacy impact using the pilot's real data
Domain: Governance, Risk, and Compliance
Q7.A quarterly security steering committee has met four times. It is chaired by the CISO, its agenda is a programme status update, and no budget has been reallocated and no enterprise risk formally accepted in a year. Business units treat attendance as optional. What change most directly turns it into a governance body?
- A.Make attendance mandatory for business unit leaders and record absences in the minutes.
- B.Add engineering and operations leads to the membership so technical decisions can be made in the room.
- C.Move the chair to an executive outside security who controls budget, and give the committee authority to approve policy, reallocate budget and accept enterprise risk.
- D.Increase the meeting frequency to monthly so decisions stop queueing between sessions.
Domain: Governance, Risk, and Compliance
Q8.A budget freeze arrives mid-year and a security programme with eleven planned initiatives must be cut to whatever the current team can sustain. The CISO must decide what continues. Which selection rule fits the constraint?
- A.Keep the initiatives with the lowest recurring cost per unit of risk reduced, plus anything a contract or regulation makes non-optional.
- B.Keep the initiatives addressing the highest inherent risk scores on the register, in rank order until the money runs out.
- C.Keep the initiatives already part-delivered so that sunk project spend is not wasted.
- D.Pause everything for the remainder of the year and resubmit the full programme at the next budget cycle.
Domain: Governance, Risk, and Compliance
Q9.A new container signing standard is ready and the architect must choose which team pilots it. Team A carries the worst inherent risk, is short-staffed and has resisted two previous security initiatives. Team B has moderate risk, a cooperative lead and a modern pipeline. There is no mandate to compel either. Which sequencing serves adoption best?
- A.Pilot with Team A, since the worst inherent risk should be addressed first.
- B.Publish the standard to both teams simultaneously with the same deadline to avoid appearing to play favourites.
- C.Pilot with Team B to produce a working reference implementation and a peer advocate, then take the proven pattern to Team A.
- D.Defer the pilot until a mandate can be obtained from the executive sponsor.
Domain: Governance, Risk, and Compliance
Q10.A board-approved policy at a healthcare SaaS provider states only that sensitive data must be encrypted. Three engineering squads have each satisfied it differently: one encrypted the database volume, one encrypted individual fields, and one decided TLS in transit was sufficient. During an internal audit all three cite the same clause and none of them is technically wrong. The board does not want the policy set reopened for re-approval. What closes the ambiguity?
- A.Reopen the policy for board re-approval so that the encryption clause names specific algorithms and key lengths.
- B.Publish a standard beneath the existing policy naming the required algorithms, key custody model and the layers at which encryption must be applied.
- C.Issue a guideline recommending field-level encryption and ask each squad to adopt it voluntarily.
- D.Write a separate procedure for each squad describing the encryption steps its own engineers must follow.
Domain: Governance, Risk, and Compliance
CompTIA SecurityX guides & exam news
CompTIA Security+ Practice Questions: 25 Exam-Style Examples With Answers and Explanations (SY0-701, 2026)
Twenty-five free CompTIA Security+ practice questions written to SY0-701 exam standard, split across the five domains in their real exam proportions, with a full explanation of every correct answer and every distractor.
Cisco CCST Cybersecurity (100-160) Explained: Domains, Cost and How It Compares to Security+ in 2026
CCST Cybersecurity costs $125 and runs 50 minutes, against $439 and 90 minutes for Security+. Here are the five exam domains, the renewal rules that changed in July 2025, and who should sit Cisco's entry-level security exam first.
Frequently Asked Questions
Does the CompTIA SecurityX course include performance-based questions?
Yes. The CompTIA SecurityX course includes 20 performance-based questions (PBQs) — hands-on tasks that mirror the interactive questions on the real exam, including drag-and-drop matching, sequencing and configuration screens. Each one is marked with partial credit, so you can see exactly which placements were wrong, and every task includes a full explanation. The first two are free to try.
What is included in the free CompTIA SecurityX sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CompTIA SecurityX course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CompTIA SecurityX course page.
Are these official CompTIA exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by CompTIA.
Which domains does the CompTIA SecurityX course cover?
The course covers 4 exam domains: Governance, Risk, and Compliance, Security Architecture, Security Engineering, Security Operations.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.