SecurityX is the pinnacle of the CompTIA security roadmap. If Security+ is the foundation, and PenTest+ and CySA+ are the intermediate levels, then SecurityX is the expert-level certification—for those who design, build, and operate security systems at a complex enterprise scale.
This certification also has a few differences that even experienced CompTIA test-takers might find surprising: the exam format is unlike other subjects, and results are not immediately displayed. This article covers all of these points.
What is SecurityX?
CompTIA SecurityX is an expert-level security certification that validates advanced technical capabilities in security architecture and high-level security engineering in cloud, on-premises, and hybrid environments. It also covers governance, risk, and compliance (GRC)—which distinguishes a senior engineer from a purely operational specialist.
This is the certification previously known as CASP+ (CompTIA Advanced Security Practitioner). CompTIA renamed it SecurityX in late 2024, along with updating the exam to version CAS-005. Those who already hold CASP+ retain its validity and receive the new badge.
A key distinguishing point: SecurityX does not test what you remember. It tests whether you can integrate governance policies, architectural design, technical controls, and operational response into a unified capability. This is a certification for technical decision-makers, not for implementers following instructions.
Exam Details
| Category | Information |
|---|---|
| Exam Code | CAS-005 |
| Former Name | CASP+ |
| Number of Questions | Maximum 90 questions |
| Duration | 165 minutes |
| Question Types | Multiple-choice + PBQ + virtual lab |
| Result | Pass/Fail — no score |
| Format | Pearson VUE, at a test center or online (OnVUE) |
| Recommended Experience | 10 years in IT, including 5 years of hands-on technical security |
| Validity | 3 years, renewed with 75 CEU |
Three details in this table are distinctly different from other CompTIA certifications, and each deserves a separate mention.
Difference 1: The exam only shows pass or fail, no score
This is the most surprising point, even for those who have taken many CompTIA certifications.
Exams like Security+, CySA+, and PenTest+ all provide a score on a 100–900 scale, and you see the result immediately on screen when you finish. SecurityX does not. The exam is purely pass/fail, CompTIA does not publish the passing threshold, and there is no converted score.
Practical consequence: you will not see your result at the end of the exam. You are notified of this at the beginning. There is also no breakdown by domain like other subjects—because there is no score to analyze.
The way to receive results is also different. Full details are in the article How to take SecurityX and receive results, but in summary: you check your exam history on the Pearson VUE system, usually about 30 minutes after finishing the exam you will see the pass/fail status, and receive official notification via email.
Difference 2: More practical questions than other exams
SecurityX has a higher proportion of practical sections than other CompTIA certifications. In addition to PBQs (performance-based questions), the exam also includes virtual labs—where you configure, analyze logs, or troubleshoot issues in a real environment.
The higher number of practical questions has a reason: this is an expert-level certification, and the only way to prove competence at that level is to make you do. You cannot just memorize your way through this section.
Details about the practical formats and how to prepare are in the article PBQ and labs in SecurityX.
Difference 3: SecurityX is the final piece to achieve CSIE
This is a lesser-known point, and a compelling reason to aim for SecurityX if you are on a long-term path within the CompTIA system.
Holders of all four CompTIA security certifications earn the CSIE title (CompTIA Security Infrastructure Expert)—a stackable certification recognizing that you have completed all four areas of security competency.
Those four pieces are:
- Security+ — foundation
- CySA+ — analysis, defense, response
- PenTest+ — controlled attacks
- SecurityX — expert-level architecture and engineering
If you already have the first three certifications, SecurityX is the final piece—and passing it not only gives you an expert-level certification but also completes the CSIE bundle. Details of this roadmap are in the article Four certifications to achieve CSIE.
Four Domains
CAS-005 consists of four domains, covering all the competencies needed to design and operate security solutions in complex environments:
| Domain | Focus |
|---|---|
| Governance, Risk & Compliance | Governance, risk assessment and management, legal and standard compliance |
| Security Architecture | Designing security architecture for infrastructure, data, applications, cloud |
| Security Engineering | Technical implementation: DevSecOps, CI/CD, automation, advanced controls |
| Security Operations | Operations, monitoring, response, analysis at enterprise scale |
The Security Architecture and Engineering sections are where most of the new content of CAS-005 is concentrated, especially concerning DevSecOps, integrating security into automated build and deployment processes, and securing cloud-native environments.
Who should study SecurityX?
Suitable if:
- You are a security engineer, security architect, or security team lead with many years of experience
- You already hold the other three CompTIA security certifications and want to complete the CSIE bundle
- You need a recognized expert-level certification for technical design and decision-making roles
- Your work involves security architecture at an enterprise scale
Not suitable if:
- You are new to the industry. SecurityX assumes many years of practical experience—start with Security+.
- You have never designed or operated real security systems. This certification tests integrated capabilities, and it is very difficult to pass by simply studying for the exam.
- You need a certification for an entry-level job. SecurityX targets senior positions.
Value of the Certification
SecurityX is included in the U.S. Department of Defense (DoD) 8140 framework for high-level roles. In Vietnam, it is suitable for positions such as security architect, security team lead, and consultant—primarily in large enterprises, banks, technology corporations, and FDI companies that adhere to international standards.
This is not a certification to "get a job" in the conventional sense, but rather a certification to affirm competence at a decision-making level—and to complete the CSIE bundle if that is your goal.
Where to Start
- Assess your practical experience against the recommended level. SecurityX is not a certification to cram for.
- Download the CAS-005 objectives from the CompTIA website—it's free.
- Determine whether you are pursuing SecurityX as a standalone certification or as the final piece of the CSIE roadmap—this will influence how you invest your time and resources.
Related Products at Security365:
- CompTIA SecurityX Online Course (CAS-005) — with genuine CertMaster Perform — 5,900,000₫ (original price 9,900,000₫). Taught in Vietnamese, covers all 4 domains, includes official practice materials.
- CompTIA SecurityX (CAS-005) genuine CertMaster Perform — 2,750,000₫ (original price 5,500,000₫), if you are self-studying.
- CAS-005 Exam Voucher with exam insurance — free 01 re-take — 9,000,000₫ (original price 11,500,000₫).
See more: Four CompTIA Certifications to Achieve CSIE · How to take SecurityX and receive results (exam does not show score) · PBQ and labs in SecurityX CAS-005