
CompTIA SecurityX (CASP+)
The CompTIA SecurityX (CASP+) certification validates advanced skills in designing and implementing secure solutions across complex environments. It is ideal for security architects and senior security engineers aiming to support resilient enterprises while addressing governance, risk, and compliance needs.
763 practice questions · Updated 2026-07-30
4Domains
27Objectives
201Concepts
763Questions
CAS-005 Curriculum
Every domain, objective, and concept the CAS-005 exam measures.
- Security Policies
- Security Procedures
- Security Standards
- Security Guidelines
- Phishing Training
- Security Training
- Privacy Training
- Communication Strategies
- Security Reporting
- RACI Matrix
- COBIT Framework Overview
- COBIT Principles
- COBIT Process Reference Model
- COBIT Goals Cascade
- COBIT Implementation
- ITIL Framework Overview
- ITIL Service Lifecycle
- ITIL Processes and Functions
- ITIL Implementation
- Comparing COBIT and ITIL
- Asset Life Cycle Management
- Configuration Management Database (CMDB)
- Asset Inventory Management
- Asset Identification and Classification
- Change Management in Configuration
- Asset Tracking and Monitoring
- Configuration Item Relationships
- Asset Disposal Procedures
- GRC Mapping
- Automation in GRC
- Compliance Tracking Tools
- Integration of GRC Tools
- Continuous Monitoring
- Data Collection for Compliance
- Reporting and Documentation
- Data Governance in Production
- Data Governance in Development
- Data Governance in Testing
- Data Governance in Quality Assurance
- Impact Analysis
- Quantitative Risk Assessment
- Qualitative Risk Assessment
- Third-Party Risk Management
- Confidentiality
- Integrity
- Availability
- Actor Characteristics
- Attack Patterns
- ATT&CK Framework
- CAPEC Framework
- STRIDE Framework
- Architecture Review
- Data Flow Analysis
- Trust Boundary Identification
- Security Implications of Architecture
- Data Flow Mapping
- Trust Boundary Management
- Risk Assessment in Architecture
- Impact of Data Flow on Security
- Trust Boundary Security Controls
- PCI DSS Overview
- PCI DSS Requirements
- ISO/IEC 27000 Series Overview
- ISO/IEC 27001 Requirements
- Industry-Specific Compliance
- NIST Framework Overview
- NIST Core Functions
- NIST Implementation Tiers
- NIST Profile Customization
- CSF Framework Overview
- CSF Core Components
- CSA Framework Overview
- CSA Security Guidance
- CSA CCM
- Framework Comparison
- Other Security Frameworks
- CASB API-based
- CASB Proxy-based
- Shadow IT Detection
- Shared Responsibility Model
- CI/CD Pipeline
- Terraform
- Ansible
- Container Security
- Orchestration
- Serverless Workloads
- Data Exposure
- Data Leakage
- Data Remanence
- Insecure Storage
- Encryption Key Management
- Proactive Controls
- Detective Controls
- Preventative Controls
- Customer-to-Cloud Connectivity
- Service Integration
- Continuous Authorization
- Network Segmentation
- Microsegmentation
- VPN Fundamentals
- Always-On VPN
- API Integration in Network Security
- Asset Identification
- Asset Management
- Asset Attestation
- Data Perimeters
- Secure Zones
- SASE Fundamentals
- SD-WAN Basics
- Software-Defined Networking (SDN) Overview
- SASE Security Services
- SD-WAN Traffic Management
- SDN Control Plane
- SASE Network Optimization
- SD-WAN Security Features
- SDN Scalability and Flexibility
- Integration of SASE and SD-WAN
- Zero Trust Principles
- Subject-Object Relationships
- Access Control Policies
- Identity and Access Management
- Microsegmentation
- Continuous Monitoring
- PowerShell Scripting
- Bash Scripting
- Python Scripting
- Event Triggers
- Infrastructure as Code (IaC)
- Cloud APIs
- Generative AI in Security
- Containerization
- Patching Automation
- Security Orchestration, Automation, and Response (SOAR)
- Workflow Automation
- Vulnerability Scanning
- Vulnerability Reporting
- SCAP Overview
- OVAL
- XCCDF
- CPE
- CVE
- CVSS
- Post-Quantum Cryptography
- Key Stretching Techniques
- Homomorphic Encryption
- Forward Secrecy
- Cryptographic Hardware Acceleration
- Data at Rest Encryption
- Data in Transit Encryption
- Data in Use Protection
- Secure Email Protocols
- Blockchain Fundamentals
- Privacy Regulations Compliance
- Certificate-Based Authentication
- Tokenization
- Code Signing
- Cryptographic Erase
- Digital Signatures
- Hashing
- Symmetric Cryptography
- Asymmetric Cryptography
- SIEM Event Parsing
- SIEM Data Retention
- SIEM False Positives and Negatives
- Aggregate Analysis Correlation
- Aggregate Analysis Prioritization
- Aggregate Analysis Trends
- Network Behavior Baselines
- Systems Behavior Baselines
- User Behavior Baselines
- Injection Attacks
- Cross-Site Scripting (XSS)
- Insecure Configurations
- Outdated Software
- Weak Ciphers
- Input Validation
- Patching
- Encryption
- Defense-in-Depth
- Internal Intelligence
- Honeypots
- User Behavior Analytics (UBA)
- External Intelligence
- Open Source Intelligence (OSINT)
- Dark Web Intelligence
- Information Sharing and Analysis Centers (ISACs)
- Threat Intelligence Platforms (TIPs)
- Indicators of Compromise (IoC) Sharing
- STIX
- TAXII
- Rule-Based Languages
- Sigma
- YARA
- Snort
- Malware Sandboxing
- Indicators of Compromise (IoC) Extraction
- Code Stylometry
- Reverse Engineering
- Metadata Analysis
- Data Recovery
- Root Cause Analysis
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CAS-005, so none is invented.