CompTIA SecurityX is the new name for CASP+ (the CompTIA Advanced Security Practitioner), delivered as exam CAS-005. It’s CompTIA’s most advanced cybersecurity certification — a hands-on, expert-level credential aimed at senior engineers and architects rather than managers.
Who it’s for
SecurityX targets practitioners with roughly ten years of IT experience including at least five hands-on in security. There are no mandatory prerequisites, but it is genuinely advanced. Unlike CISSP, which leans managerial, SecurityX stays technical — it’s often described as the cert for people who want to keep building and breaking, not just governing.
The four domains
- Security Architecture — designing secure enterprise, cloud, and hybrid environments.
- Security Operations — threat management, monitoring, incident response, and analytics.
- Security Engineering & Cryptography — secure implementations, PKI, and emerging tech.
- Governance, Risk & Compliance — risk, frameworks, and regulatory alignment.
Exam format
Expect up to 90 questions in 165 minutes, mixing multiple-choice with performance-based questions that put you in simulated scenarios. This is the part candidates underestimate — you need applied judgment, not just recall. SecurityX is also a DoD 8140-relevant, ANAB-accredited credential, which matters for government and contractor roles.
How to prepare
Because the exam emphasizes applied decision-making, the most effective prep is high volume of scenario-based practice questions across all four domains, reviewing the reasoning behind every answer. Focus especially on architecture and engineering — they carry the most technical depth.