CompTIA CASP+ (SecurityX) (CAS-005) Exam Blueprint

CAS-005

90Questions
165 minDuration
$509Price
3 yearsValid For
4Languages
Practice CompTIA CASP+ (SecurityX) on QuizForge

Exam Domains

1.0 Governance, risk, and compliance 20%
  • 1.1Security program documentation
    policies, procedures, standards, and guidelines.
  • 1.2Program management
    training (phishing, security, privacy), communication, reporting, and RACI matrix.
  • 1.3Frameworks
    COBIT, ITIL, etc.
  • 1.4Configuration management
    asset life cycle, CMDB, and inventory.
  • 1.5GRC tools
    mapping, automation, and compliance tracking.
  • 1.6Data governance
    production, development, testing, and QA.
  • 1.7Risk management
    impact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability.
  • 1.8Threat modeling
    actor characteristics, attack patterns, and frameworks (ATT&CK, CAPEC, STRIDE).
  • 1.9Attack surface
    architecture reviews, data flows, and trust boundaries.
  • 1.10Compliance strategies
    industry-specific standards (PCI DSS, ISO/IEC 27000).
  • 1.11Security frameworks
    NIST, CSF, CSA, and others.
2.0 Security architecture 27%
  • 2.1Cloud capabilities
    CASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads.
  • 2.2Cloud data security
    data exposure, leakage, remanence, insecure storage, and encryption keys.
  • 2.3Cloud control strategies
    proactive, detective, and preventative controls; customer-to-cloud connectivity, service integration, and continuous authorization.
  • 2.4Network architecture
    segmentation, microsegmentation, VPN, always-on VPN, and API integration.
  • 2.5Security boundaries
    asset identification, management, attestation, data perimeters, and secure zones.
  • 2.6Deperimeterization
    SASE, SD-WAN, and software-defined networking.
  • 2.7Zero trust concepts
    defining subject-object relationships.
3.0 Security engineering 31%
  • 3.1Automation
    scripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation.
  • 3.2Vulnerability management
    scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS).
  • 3.3Advanced cryptography
    PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration.
  • 3.4Cryptographic use cases
    data at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication.
  • 3.5Cryptographic techniques
    tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography.
4.0 Security operations 22%
  • 4.1Monitoring and data analysis
    SIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users).
  • 4.2Vulnerabilities and attack surface
    injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth.
  • 4.3Threat hunting
    internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort).
  • 4.4Incident response
    malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis.

Exam Details

Question TypesMultiple Choice (single), Multiple Choice (multiple), Performance-Based
FormatLinear
Online ProctoringAvailable
ID RequirementsTwo forms of ID are required. Primary ID must be government-issued, include candidate's name, photo, and signature (e.g. passport, driver's license). Secondary ID must include candidate's name and signature or name and photo.
RenewalRequired -- Earn CE credits through CompTIA CE program (training, conferences, publishing, teaching, higher certs) or retake the current exam version before expiry.
PrerequisitesNetwork+, Security+, CySA+, Cloud+, and PenTest+ or equivalent knowledge (recommended)
Retake PolicyNo waiting period required before first retake. After the second failed attempt, candidates must wait 14 calendar days before any subsequent attempt. No limit on total attempts.
LanguagesEnglish, Japanese, Portuguese, Simplified Chinese

Official Study Resources

online courseCertMaster Learn ($499)
practice examCertMaster Practice ($99)
labCertMaster Labs ($199)