CompTIA SecurityX · CAS-005 · formerly CASP+

CompTIA SecurityX (CAS-005) Full-Length Practice Test

Each practice test uses the published maximum length: 90 questions in 165 minutes. Ten independent papers cover the four CAS-005 domains with the same fixed blueprint, including six clearly marked choose-TWO questions in every test.

  • 90 questions / 165 min
  • Pass/fail live exam
  • 6 choose-TWO per test
  • 4 CAS-005 domains
  • 10 independent tests
From$2₹99£1.47€1.70per full-length practice test
10Full-length tests
900Questions in total
Pass/FailOfficial result model
4CAS-005 domains
SecurityX full-length practice tests

Choose one test, five tests, or the complete set

Every test contains 90 questions, runs for 165 minutes, and uses the same 18 / 24 / 28 / 20 domain allocation. The complete set gives you 900 questions without changing the blueprint from one paper to the next.

One test

90 questions

$2₹99£1.47€1.70

One complete 165-minute practice run

  • 90 CAS-005 questions
  • All four domains in the fixed blueprint
  • Six choose-TWO questions
  • Easy, medium and hard scenarios
Start with test 1
Best value pack

All 10 tests

900 questions

$9₹499£6.60€7.69

Ten independent full-length practice tests

  • 900 questions across CAS-005 objectives V3.0
  • Same domain and difficulty matrix in every test
  • 60 choose-TWO questions across the set
  • Ten fresh papers for repeated timed practice
Get all 10 tests

Five tests

450 questions

$5₹299£3.67€4.27

Five complete 165-minute practice runs

  • 450 CAS-005 questions
  • Same 18 / 24 / 28 / 20 domain allocation
  • 30 choose-TWO questions across the pack
  • Five separate tests for spaced practice
Get 5 tests
The exam you’re preparing for

What CompTIA sets on SecurityX CAS-005

SecurityX is CompTIA’s expert-level security certification. CAS-005 launched on 17 December 2024 and reports only pass or fail, with no published scaled score.

CompTIA SecurityX CAS-005 exam specification
Exam codeCAS-005
CertificationCompTIA SecurityX
Launched17 December 2024
QuestionsMaximum of 90
Duration165 minutes
Question typesMultiple-choice and performance-based
Passing resultPass/fail only; no scaled score
Recommended experience10 years hands-on IT, including 5 years broad hands-on IT security
U.S. exam voucher$544 USD

Written to the current CAS-005 objectives

The question banks use CompTIA SecurityX CAS-005 Exam Objectives Version 3.0. The four domains are Governance, Risk, and Compliance; Security Architecture; Security Engineering; and Security Operations.

This is senior-practitioner material. The questions focus on architecture trade-offs, engineering choices, cloud and hybrid design, identity, cryptography, automation, threat hunting, incident response, governance and AI security.

The live exam also contains performance-based questions. These practice tests cover the multiple-choice body with single-answer and choose-TWO questions; hands-on tasks still belong in a lab.

Inside a test

Two hours and forty-five minutes leaves room to reason. It also exposes hesitation.

SecurityX is not Security+ with longer wording. A strong answer often loses because it ignores one constraint: trust boundary, recovery requirement, authorization path, evidence quality or operational impact.

How it’s built

  • 90 questions in a 165-minute practice window
  • 18 Governance, Risk, and Compliance questions
  • 24 Security Architecture questions
  • 28 Security Engineering questions
  • 20 Security Operations questions
  • Six choose-TWO questions in every test

Difficulty and answer format

  • 14 easy, 41 medium and 35 hard questions
  • 84 single-answer questions
  • Six choose-TWO questions, scored all-or-nothing
  • No negative marking in these practice tests
  • Scenario-led BEST, FIRST, NEXT and MOST decisions
  • The same matrix runs through all ten papers

What you review

  • Every question carries a student-facing explanation
  • The explanation resolves why the keyed answer wins
  • The strongest wrong answer is addressed where it matters
  • Questions are mapped to the CAS-005 domain and objective
  • That makes a repeated weak area easier to spot across papers
Worked example from the question bank

The hard part is seeing the blind spot the diagram did not show

This question comes from SecurityX Practice Test 3. Both correct choices address a different gap in the same threat model.

Governance, Risk & ComplianceThreat modelingChoose TWOHard

An enterprise is threat-modeling an externally exposed collaboration platform before a major divestiture. The team wants to uncover risks that ordinary architecture diagrams may miss, especially around misuse by legitimate users and services that were created outside formal IT processes. Which TWO activities are MOST valuable?

  • ADevelop abuse cases that describe how authorized capabilities could be misused
  • BRestrict the review to known vulnerability scanner findings on managed servers
  • CAssume existing trust relationships remain valid until the divestiture is complete
  • DEnumerate unsanctioned assets and accounts connected to the platform

Why A and D

Abuse cases expose harmful uses of legitimate functions. Enumerating unsanctioned assets and accounts finds attack surface that ordinary architecture diagrams can miss. Together they cover misuse and shadow resources.

Why B and C miss the requirement

Vulnerability findings alone do not model misuse by legitimate capabilities. Assuming inherited trust is safe is exactly the kind of blind spot a divestiture threat model should challenge.

CAS-005 domain weighting

Every 90-question paper uses the same four-domain allocation

Security Engineering is the largest domain at 31%, followed by Security Architecture at 27%. The practice blueprint converts those percentages into a fixed whole-question split so one paper can be compared with the next.

CAS-005 domainCompTIA weightQuestions per practice testPractice share
1.0 Governance, Risk, and Compliance20%1820.0%
2.0 Security Architecture27%2426.7%
3.0 Security Engineering31%2831.1%
4.0 Security Operations22%2022.2%

Architecture and Engineering account for 52 of the 90 questions in each practice test.

Questions

About the SecurityX exam and these practice tests

The CAS-005 exam

How many questions are on CompTIA SecurityX CAS-005?
CompTIA publishes a maximum of 90 questions. The live exam can contain fewer. These full-length practice tests deliberately use the full 90-question maximum.
How long is the SecurityX exam?
The CAS-005 time limit is 165 minutes.
What score do you need to pass SecurityX?
CompTIA reports SecurityX as pass or fail only. CAS-005 has no published scaled score and no published percentage passing mark.
What are the four SecurityX CAS-005 domains?
Governance, Risk, and Compliance is 20%; Security Architecture is 27%; Security Engineering is 31%; and Security Operations is 22%.
How much does the SecurityX CAS-005 exam cost?
The current U.S. list price is $544 USD for the SecurityX exam voucher.
What experience does CompTIA recommend?
CompTIA recommends at least 10 years of general hands-on IT experience, including at least five years of broad hands-on IT security experience.
If I fail SecurityX, when can I retake it?
There is no waiting period between the first and second attempt. Before the third attempt and each later attempt, CompTIA requires at least 14 calendar days from the previous attempt.
Is SecurityX the replacement for CASP+?
Yes. CompTIA renamed the certification SecurityX when CAS-005 launched on 17 December 2024. CAS-005 is the current exam for the certification.
Does the live SecurityX exam contain performance-based questions?
Yes. CompTIA lists multiple-choice and performance-based questions for CAS-005. These practice tests cover the multiple-choice portion with single-answer and choose-TWO questions, so hands-on PBQ work should be practised separately in a lab.

These practice tests

How many questions are in each full-length SecurityX practice test?
Each test contains exactly 90 questions and uses a 165-minute practice window. Five tests contain 450 questions; all ten contain 900.
How are the 90 practice questions distributed?
Each paper uses 18 Governance, Risk, and Compliance questions, 24 Security Architecture questions, 28 Security Engineering questions, and 20 Security Operations questions.
Do the tests include choose-TWO questions?
Yes. Every paper contains six choose-TWO questions alongside 84 single-answer questions. Both correct choices are required for the choose-TWO item to score.
What difficulty mix is used?
Every test contains 14 easy, 41 medium and 35 hard questions. The same matrix is used throughout the ten-test series.
Do the questions include explanations?
Yes. Every question bank includes a student-facing explanation that resolves the correct choice and addresses the strongest distractor or deciding constraint.
Is there negative marking on these practice tests?
No. Wrong answers do not subtract marks. Choose-TWO questions are scored all-or-nothing.
Can I buy one test instead of a pack?
Yes. You can start with any single test, choose the five-test pack, or buy the complete ten-test set.
Ready when you are

Ten SecurityX practice tests. 900 questions.
$9₹499£6.60€7.69

A U.S. SecurityX exam voucher is $544. Use the full set to find repeated gaps in architecture, engineering, operations and GRC before they show up on exam day.

Authors

  • Security Practice Test Editorial Team

    Security Practice Test Editorial Team is the expert content team at SecurityPracticeTest.com dedicated to producing authoritative cybersecurity certification exam-prep resources. We create comprehensive practice tests, study materials, and exam-focused content for top security certifications including CompTIA Security+, SecurityX, PenTest+, CISSP, CCSP, SSCP, Certified in Cybersecurity (CC), CGRC, CISM, SC-900, SC-200, AZ-500, AWS Certified Security - Specialty, Professional Cloud Security Engineer, OSCP+, GIAC certifications, CREST certifications, Check Point, Cisco, Fortinet, and Palo Alto Networks exams. Our content is developed through careful review of official exam objectives, cybersecurity knowledge domains, and practical job-relevant concepts to help learners build confidence, strengthen understanding, and prepare effectively for certification success.

  • Sudhanshu Thakur - Reviewer

    Enterprise Technology and Digital Transformation Professional with 18+ years of experience in enterprise software, SaaS, industrial automation, and business consulting. Formerly associated with Rockwell Automation, Tech Mahindra, Emerson, ABB, L&T Infotech, and Hewlett Packard Enterprise.