Try CompTIA SecurityX
Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.
Get full access to CompTIA SecurityX
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
This course
$9.99
one-time
Monthly
$12.99
per month · all courses
Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in
CompTIA · Exam reference
About the CompTIA SecurityX exam
SecurityX (CAS-005) is CompTIA's expert-level security certification and the exam that CASP+ became. It covers governance and risk, security architecture, security engineering and security operations for practitioners who design and build controls rather than monitor them.
10
Sample questions
165 min
Exam time limit
70%
Passing score
$499
Exam voucher
CompTIA SecurityX carries the exam code CAS-005 and replaces CASP+. The blueprint changed along with the name. Four domains split the exam: governance, risk and compliance at 20 percent, security architecture at 27 percent, security engineering at 31 percent, and security operations at 22 percent. Well over half of it therefore sits in architecture and engineering, which is where candidates arriving from Security+ or CySA+ lose most of their marks. Those two domains ask you to choose a design and defend it against constraints such as legacy systems that cannot be patched, regulatory scope, a merger that has to be integrated, and a fixed budget. Recalling what a control does will not answer them. The exam runs up to 90 questions in 165 minutes and mixes multiple-choice items with performance-based tasks. CompTIA reports it as pass or fail with no scaled score, so there is no published number to aim at. Treat every domain as one you have to be competent in rather than one you can average away. SecurityX is written for people already doing the work: security architects, senior engineers, technical leads and consultants who own designs rather than tickets. CompTIA keeps it a practitioner credential rather than a management one, so the questions stay technical even inside the governance domain, where you are asked how a control satisfies a requirement and what evidence would prove it. This course follows the CAS-005 objectives domain by domain, with practice questions, flashcards and performance-based tasks weighted the way the real exam is.
Exam Domains Covered
Exam Format & Details
Up to 90 questions in 165 minutes, mixing multiple-choice items with performance-based tasks. CompTIA reports the result as pass or fail and publishes no scaled passing score for CAS-005. The CompTIA Store lists the individual voucher at USD 499. Booked through Pearson VUE, at a test centre or online.
Why Practice Questions Matter
SecurityX questions are long. One item can run a full paragraph of context before it asks anything, and all four answers are often defensible controls with a single one that fits the constraint buried in the scenario. What you practise here is finding that constraint before you read the options, which is a reading habit rather than a recall drill. Several hundred questions in this format teach you to spot the sentence that decides the answer, and every explanation says why the near-miss option fails, because that distinction is what the exam actually tests.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CompTIA SecurityX exam — not actual exam content.
Q1.A newly appointed CISO at a 900-person manufacturer finds that every disagreement about a security decision resolves in favour of whichever director argues hardest. There is a signed acceptable use policy and a draft multi-factor authentication standard, but no agreement on what the security function may decide by itself and what it may only recommend. Which document addresses the root problem?
- A.A charter establishing the security function, its reporting line, and the decisions it can make unilaterally versus recommend.
- B.An expanded acceptable use policy that lists disciplinary consequences for non-compliance.
- C.A RACI matrix covering the current multi-factor authentication rollout.
- D.An approved multi-factor authentication standard that engineering must implement.
Domain: Governance, Risk, and Compliance
Q2.A regulator examining a payments platform asks for evidence that multi-factor authentication is enforced on every system processing cardholder data. The security team sends the board-approved access control policy and the Statement of Applicability row marking the control as applicable. The regulator repeats the request unchanged. Which two items answer the question actually asked? Select two.
- A.An export of the identity provider's conditional access configuration for the in-scope systems, together with the current approved exclusion list.
- B.Signed quarterly access review records showing who reviewed which accounts and what was remediated.
- C.A memo from the CISO confirming that the access control policy is mandatory for all staff.
- D.The vendor datasheet for the authenticator product currently deployed.
- E.A steering committee minute recording approval of the access control policy.
Domain: Governance, Risk, and Compliance
Q3.A board has signed a one-page risk appetite statement whose strongest line reads: "We have a low appetite for cyber risk." At a design review for a new claims portal, the architect cannot use any line in the statement to settle whether a proposed shared administrative account is inside or outside appetite. The chief risk officer wants the statement fixed before the next board cycle. What should the architect propose?
- A.Map the appetite statement onto framework implementation tiers so the board can track a single maturity score each quarter.
- B.Attach a five by five heat map so the board can see which current risks fall outside appetite.
- C.Obtain a fresh board signature on the existing wording so the statement has a documented owner and date.
- D.Rewrite each line so it yields a number, a boundary or a named approver, and test that an architect can derive at least one design decision from every line before it returns to the board.
Domain: Governance, Risk, and Compliance
Q4.A member services platform falls under an appetite statement that accepts up to four hours of recovery time and up to fifteen minutes of data loss. The disaster recovery budget is fixed and will not stretch to a second live production footprint. Which design satisfies the stated constraints?
- A.Nightly offsite backups with a documented six-hour restore commitment from the recovery vendor.
- B.Near-continuous replication to a warm secondary, with a documented and rehearsed failover schedule.
- C.Hourly snapshot shipping to a standby region, with restores rehearsed twice a year.
- D.Active-active deployment across two regions with automatic traffic steering.
Domain: Governance, Risk, and Compliance
Q5.An operations team has configured its paging rule for a customer-facing outage to fire at four hours, matching the figure in the approved risk appetite statement exactly. The service owner argues that alerting any earlier would generate noise. What should the security architect advise?
- A.Set escalation at three hours so the tolerance band leaves room to react before the appetite figure is breached.
- B.Keep the four-hour trigger and rely on the post-incident review to catch repeated near-breaches.
- C.Ask the board to widen appetite to six hours so the four-hour alert becomes an early warning.
- D.Replace the time-based alert with a severity-based one raised by the on-call engineer's judgement.
Domain: Governance, Risk, and Compliance
Frequently Asked Questions
What is included in the free CompTIA SecurityX sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CompTIA SecurityX course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CompTIA SecurityX course page.
Are these official CompTIA exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by CompTIA.
Which domains does the CompTIA SecurityX course cover?
The course covers 4 exam domains: Governance, Risk, and Compliance, Security Architecture, Security Engineering, Security Operations.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.