Credential type: certification examination · verified on the issuer's site September 19, 2026 issuer page
What This Exam Validates
The CompTIA CASP+ certification exam, offered by CompTIA, evaluates technical security skills across 4 distinct domains. Candidates face a total of 90 questions delivered in a linear format with a duration of 165 minutes. The exam tests advanced concepts in governance, security architecture, engineering, and operations to measure extensive cybersecurity expertise.
Who Should Take This Exam
Experienced cybersecurity professionals and advanced practitioners seeking to validate their senior-level technical knowledge, architecture design skills, and operational risk management capabilities should take this exam.
Skills You Should Be Ready to Demonstrate
- Security program documentation
- Cloud capabilities
- Automation
- Vulnerability management
- Advanced cryptography
- Threat hunting
How to Prepare
Review all official study documentation and practice materials in extensive detail. Focus your study plan across all 4 domains, giving specific attention to cloud data security, automation, advanced cryptography, and threat hunting techniques to successfully prepare for performance-based questions and multiple choice items during the testing period.
Domain Study Guidance
Governance, risk, and compliance: Study Guidance
Covers governance, risk, and compliance with a 20.0 percent weight, focusing heavily on program management, frameworks, and vital security program documentation required for organizational security compliance and standard operations.
- Security program documentation
- Program management
- Frameworks
Security architecture: Study Guidance
Focuses on security architecture with a 27.0 percent weight, addressing cloud capabilities, cloud data security, and tailored control strategies for complex enterprise environments to ensure strong protection of digital assets across systems.
- Cloud capabilities
- Cloud data security
- Cloud control strategies
Security engineering: Study Guidance
Presents security engineering concepts carrying a 31.0 percent weight, including automation, vulnerability management, and advanced cryptography designed to secure modern systems against evolving threats and infrastructure vulnerabilities encountered in professional environments.
- Automation
- Vulnerability management
- Advanced cryptography
Security operations: Study Guidance
Involves security operations carrying a 22.0 percent weight, concentrating on monitoring and data analysis, vulnerabilities and attack surfaces, alongside proactive threat hunting methodologies utilized for effective incident detection and response.
- Monitoring and data analysis
- Vulnerabilities and attack surface
- Threat hunting
Exam-Day Guidance
Manage your 165-minute time allocation carefully across all 90 questions. Review performance-based questions and multiple choice items carefully before submitting your final answers for grading.
Frequently asked questions
How many questions are on the exam?
The exam consists of a total of 90 questions presented in a linear format, utilizing multiple choice single, multiple choice multiple, and performance-based question types to assess your knowledge.
What is the passing score?
The passing score for this credential uses a scale of 100-900, reflecting the scoring metrics carefully defined by CompTIA for this professional cybersecurity certification program and its candidates.
How long is the exam?
The exam has a total duration of 165 minutes to complete all 90 questions within the scheduled testing period provided at the test center location.
What is the price of the exam?
The exam price is set at $509.0 USD, which is required when registering for the CompTIA CASP+ certification voucher and scheduling your test appointment.
Sources and Verification
Verified 2026-08-30
How this page was made
This detailed page was built thoroughly using verified facts and official documentation sources obtained directly from CompTIA certification and training programs.
Exam Domains
1.0 Governance, risk, and compliance
20%
- 1.1Security program documentation
policies, procedures, standards, and guidelines.
- 1.2Program management
training (phishing, security, privacy), communication, reporting, and RACI matrix.
- 1.3Frameworks
COBIT, ITIL, etc.
- 1.4Configuration management
asset life cycle, CMDB, and inventory.
- 1.5GRC tools
mapping, automation, and compliance tracking.
- 1.6Data governance
production, development, testing, and QA.
- 1.7Risk management
impact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability.
- 1.8Threat modeling
actor characteristics, attack patterns, and frameworks (ATT&CK, CAPEC, STRIDE).
- 1.9Attack surface
architecture reviews, data flows, and trust boundaries.
- 1.10Compliance strategies
industry-specific standards (PCI DSS, ISO/IEC 27000).
- 1.11Security frameworks
NIST, CSF, CSA, and others.
2.0 Security architecture
27%
- 2.1Cloud capabilities
CASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads.
- 2.2Cloud data security
data exposure, leakage, remanence, insecure storage, and encryption keys.
- 2.3Cloud control strategies
proactive, detective, and preventative controls; customer-to-cloud connectivity, service integration, and continuous authorization.
- 2.4Network architecture
segmentation, microsegmentation, VPN, always-on VPN, and API integration.
- 2.5Security boundaries
asset identification, management, attestation, data perimeters, and secure zones.
- 2.6Deperimeterization
SASE, SD-WAN, and software-defined networking.
- 2.7Zero trust concepts
defining subject-object relationships.
3.0 Security engineering
31%
- 3.1Automation
scripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation.
- 3.2Vulnerability management
scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS).
- 3.3Advanced cryptography
PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration.
- 3.4Cryptographic use cases
data at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication.
- 3.5Cryptographic techniques
tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography.
4.0 Security operations
22%
- 4.1Monitoring and data analysis
SIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users).
- 4.2Vulnerabilities and attack surface
injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth.
- 4.3Threat hunting
internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort).
- 4.4Incident response
malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis.
Exam Details
Question TypesMultiple Choice (single), Multiple Choice (multiple), Performance-Based
FormatLinear
Online ProctoringAvailable
ID RequirementsTwo forms of ID are required. Primary ID must be government-issued, include candidate's name, photo, and signature (e.g. passport, driver's license). Secondary ID must include candidate's name and signature or name and photo.
RenewalRequired -- Earn CE credits through CompTIA CE program (training, conferences, publishing, teaching, higher certs) or retake the current exam version before expiry.
PrerequisitesNetwork+, Security+, CySA+, Cloud+, and PenTest+ or equivalent knowledge (recommended)
Retake PolicyNo waiting period required before first retake. After the second failed attempt, candidates must wait 14 calendar days before any subsequent attempt. No limit on total attempts.
LanguagesEnglish, Japanese, Portuguese, Simplified Chinese