What the CompTIA SecurityX CAS-005 is and who it is for
CompTIA SecurityX is CompTIA’s most advanced cybersecurity certification. It was previously known as CASP+ and has been rebranded as part of the Xpert series. The current version is V5, exam code CAS-005, launched on 17 December 2024. It validates expert level skills in security architecture, security engineering, governance, risk and compliance, and security operations across complex enterprise environments, including cloud, hybrid and on premises estates.
This is an exam for senior practitioners. CompTIA recommends ten years of IT experience, including five years of hands on security experience, before you attempt it. It is DoD 8140/8570 approved at expert level, which matters if you work in, or want to work in, US government and defence roles, where that approval is frequently a hard requirement. In the wider market it is treated as a direct competitor to CISSP and CISM for senior security jobs.
CompTIA SecurityX CAS-005 at a glance
| Item | Detail |
|---|---|
| Exam code | CAS-005 |
| Questions | Up to 90, including performance based questions |
| Time allowed | 165 minutes |
| Passing score | Pass or fail only, no scaled score is reported |
| Exam fee | US$544 |
| Where you sit it | Pearson VUE testing centres and online proctored |
| Certification valid for | 3 years |
What is on the exam
The CAS-005 blueprint has four domains. The weights tell you roughly how much of your question set each one supplies, so they should shape how you split your study time.
Governance, risk and compliance (20%). This domain covers the management side of security: how an organisation decides what risk it will accept, how it aligns controls with legal, regulatory and contractual obligations, and how it governs a security programme over time. Expect questions that ask you to weigh business impact against technical options, rather than questions with a purely technical answer.
Security architecture (27%). Architecture is about designing secure systems before they are built. Questions here present an enterprise environment, often mixing cloud, hybrid and on premises components, and ask you to choose the design that meets a set of security, resilience and business requirements. You need to reason about trade offs, not just recognise a control by name.
Security engineering (31%). The largest domain. Engineering is the implementation side: configuring, integrating and troubleshooting security technologies so that the architecture actually works in production. This is where the exam expects you to get hands on with a scenario and produce a working answer rather than describe one.
Security operations (22%). Operations covers what happens once systems are live: monitoring, threat and vulnerability management, incident handling and the analysis that feeds back into governance and architecture. Scenario questions here hand you evidence and ask what you should do next.
Why people fail it
The first reason is the format. SecurityX is not a multiple choice only exam. Performance based questions put you inside a realistic security scenario and expect you to make the call, not just recognise the right term.
The second is the scoring. The exam is pass or fail only. There is no scaled score, no partial credit and no score report telling you how close you came. A near miss counts the same as a wide one, and you walk out with no data about which domains let you down.
The third is the cost of getting it wrong. A SecurityX voucher is US$544, the most expensive exam in CompTIA’s catalogue. Fail and you pay the full amount again. Candidates who know the material but underestimate the scenario framing end up paying twice.
A study plan that fits the exam
The plan below runs eight weeks and weights each domain roughly in line with the blueprint: engineering gets the most time, architecture next, then operations and governance. Adjust the split if you already work in one of these areas every day.
- Week 1: baseline and governance, risk and compliance. Start by working through the free CAS-005 practice questions under exam conditions so you know what the question style feels like before you open a study guide. Then cover the governance domain: risk management, compliance obligations and how security decisions are justified to the business.
- Weeks 2 and 3: security architecture. Spend two weeks on secure design across enterprise, cloud and hybrid environments. For every design pattern you study, write down the requirements it satisfies and the situations where it is the wrong choice, because that is how the exam frames its architecture questions.
- Weeks 4, 5 and 6: security engineering. Three weeks for the largest domain. Focus on implementation and troubleshooting rather than definitions. This is the block to start the CAS-005 practice pack in earnest: work through the engineering questions with the explanations open, and keep a list of every wrong option you would have picked and why it was wrong.
- Week 7: security operations. Cover monitoring, incident handling and vulnerability management, then run the operations questions from the pack. Look for patterns in what the scenarios ask you to do next.
- Week 8: timed full runs. Use the questions only PDF to sit at least two full length timed sessions of 90 questions in 165 minutes. Review every miss against the explanation, then spend the final few days on your weakest domain.
On exam day
You can sit CAS-005 at a Pearson VUE testing centre or online with a proctor. If you choose the online option, check the room, desk and equipment rules with Pearson VUE well before the day, because a failed check in can cost you the appointment.
You have up to 165 minutes for up to 90 questions. That averages under two minutes per question, but performance based questions take far longer than multiple choice ones, so do not spend the average on the easy items. Move quickly through the multiple choice questions, flag anything you are unsure about, and bank time for the scenarios. Read each PBQ fully before touching anything, because the scenario usually contains the constraint that decides the answer.
The result is pass or fail. You will not get a scaled score or a domain breakdown, so make sure your last timed practice runs were where you found your weak spots, not the exam itself.
Frequently asked questions
Can I retake the CAS-005 if I fail?
Yes, but each attempt costs the full US$544 voucher again. CompTIA publishes its own retake policy, including any waiting period between attempts, so check the current rules on the vendor page before you book a second sitting. Because the exam only reports pass or fail, plan a retake around your own practice data rather than a score report you will not receive.
Is the practice pack enough on its own?
No. The pack is 475 practice questions with explanations, MCQ and PBQ, mapped to the CAS-005 objectives. It is a tool for checking what you know, learning the scenario framing and finding gaps. It is not a course, and at expert level the exam assumes real experience across all four domains. Use it alongside the official objectives, your own hands on work and whatever study material fills the gaps it exposes.
How is SecurityX different from CASP+?
SecurityX is the rebranded and expanded successor to CASP+, now part of CompTIA’s Xpert series. The current version is V5 with the series code CAS-005, launched on 17 December 2024. The certification is valid for three years.
Do I need a specific certification before I sit it?
CompTIA’s guidance is experience based: ten years of IT experience, including five years of hands on security, is recommended. Check the vendor page for any formal prerequisite before booking.
Get the CompTIA SecurityX CAS-005 practice pack, 475 questions with full explanations, pass or your money back.
