CompTIA SecurityX CAS-005 Certification Exam

CompTIA SecurityX CAS-005

The CompTIA SecurityX CAS-005 certification (formerly CASP+) validates the advanced skills senior security professionals use to architect, engineer, and operate enterprise security solutions. The exam covers four domains: governance, risk, and compliance; security architecture; security engineering; and security operations. Candidates demonstrate expert-level judgment in zero trust and hybrid cloud architecture, IAM federation, cryptographic solutions, incident response, and risk management, analyzing exhibits such as network diagrams, IAM policies, IaC snippets, and audit findings to make defensible architectural and governance decisions. The exam has a maximum of 90 questions over 165 minutes.

Certification Overview

  • Exam name: SecurityX CAS-005
  • Vendor: CompTIA
  • Exam code: CAS-005
  • Duration: 165 minutes
  • Total questions: 90
  • Passing score: 75%

Who Should Take This Exam?

Security Architect, Senior Security Engineer, Security Analyst, Security Consultant, SOC Manager, Security Engineer, Cloud Security Architect

Prerequisites

No formal prerequisite. CompTIA recommends Security+, CySA+ and PenTest+ or equivalent knowledge, plus 10 years of general IT experience including 5 years of security experience.

Topics Covered

  • Governance, Risk, and Compliance
  • Security Architecture
  • Security Engineering
  • Security Operations

Question Types

  • Multiple Choice (Single Answer)
  • Multiple Choice (Multiple Answers)
  • Drag and Drop
  • Scenario-Based

SecurityX CAS-005 Practice Questions

Our question bank contains 654+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.

Governance, Risk, and Compliance

Which TWO governance documents work together to define mandatory technical baselines and the step-by-step instructions for applying them? (Choose two)
  • Memoranda of understanding
  • Procedures
  • Policies
  • Guidelines
  • Standards
An organization is evaluating a new threat and wants to determine both how often the threat is expected to occur and how much financial loss a single occurrence would cause. Which TWO quantitative risk values must the analyst calculate first? (Choose two)
  • Annualized loss expectancy (ALE)
  • Single loss expectancy (SLE)
  • Residual risk rating
  • Mean time to repair (MTTR)
  • Annualized rate of occurrence (ARO)
A company operating in the EU and the United States must comply with GDPR and various U.S. state privacy laws. Which TWO obligations are shared by GDPR and the California Consumer Privacy Act (CCPA)? (Choose two)
  • Mandating annual penetration testing of consumer-facing applications
  • Requiring disclosure of what categories of personal information are collected and for what purposes
  • Requiring appointment of a Data Protection Officer (DPO)
  • Imposing a mandatory 72-hour breach notification window to a supervisory authority
  • Granting individuals the right to request deletion of their personal data

Security Architecture

Which TWO resilience strategies, when combined, allow an application to survive the complete loss of a data center while maintaining an RPO of near-zero? (Choose two)
  • Automated DNS failover that redirects traffic to the surviving site
  • Disabling monitoring alerts during the failover window
  • Weekly tape backups shipped to an offsite vault
  • Synchronous database replication to a standby in a second data center
  • Manual re-provisioning of servers from scratch after the failure
Which TWO security activities should be performed during the design phase of the SSDLC before any code is written? (Choose two)
  • Decommissioning old infrastructure
  • Defining security requirements and abuse cases alongside functional requirements
  • Penetration testing of the production deployment
  • Threat modeling to identify attack surfaces in the proposed architecture
  • Dynamic application security testing (DAST) of the running application
An architect designs a defense-in-depth architecture for a web application. Which TWO controls operate at different layers to protect against SQL injection? (Choose two)
  • DNSSEC on the application's domain
  • A WAF with SQL-injection detection rules at the network perimeter
  • A VPN tunnel between the user and the application server
  • Parameterized queries (prepared statements) in the application code
  • Full-disk encryption on the database server

Security Engineering

A security engineer hardens a Linux web server. Which TWO configurations reduce the attack surface of the server's SSH service? (Choose two)
  • Disabling root login by setting PermitRootLogin to no in the SSH daemon configuration
  • Enabling SSH protocol version 1 as a fallback for legacy clients
  • Increasing the SSH session idle timeout to 24 hours so administrators are not disconnected during long tasks
  • Restricting SSH access to specific user groups via the AllowGroups directive
  • Configuring the SSH banner to display the server's operating system version
An organization implements a zero-trust network architecture. Which TWO controls are foundational to a zero-trust model? (Choose two)
  • Continuous verification of user identity and device posture before granting access to each resource
  • Granting full network access to all users who connect through the corporate VPN
  • Relying on perimeter firewalls as the sole access control mechanism for internal resources
  • Micro-segmentation that enforces least-privilege access policies between individual workloads
  • Using a single shared service account for all internal application-to-application communication
Which TWO practices ensure that an organization's Hardware Security Module (HSM) key management meets regulatory requirements for financial data encryption? (Choose two)
  • Maintaining tamper-evident audit logs of all key lifecycle events including creation, rotation, and destruction
  • Allowing any administrator to independently export HSM key material for backup purposes
  • Storing HSM backup tokens in the same data center as the primary HSM
  • Using the HSM's default factory-set master key without generating a custom key hierarchy
  • Implementing dual-control and split-knowledge procedures for all HSM key ceremony operations

Security Operations

A SIEM analyst configures log correlation rules. Which TWO log sources, when correlated, provide the strongest detection for lateral movement via stolen credentials? (Choose two)
  • EDR telemetry showing the source workstation executing credential dumping tools before the network logon occurred on the target
  • DHCP server logs showing IP address lease renewals for known workstations
  • Print server logs showing print jobs submitted by the user
  • Windows Security event logs showing successful logon events (Event ID 4624) with logon type 3 (network) from unusual source workstations
  • NTP synchronization logs from the domain controllers
Which TWO activities are part of the containment phase of incident response? (Choose two)
  • Updating the organization's security awareness training materials
  • Isolating the compromised network segment to prevent the attacker from moving to additional systems
  • Publishing a press release about the security incident
  • Blocking the attacker's known C2 IP addresses and domains at the firewall and DNS to cut off communication
  • Conducting a root cause analysis to determine how the attacker initially gained access
Which TWO data sources are most valuable for a threat hunter investigating potential data staging before exfiltration on Windows endpoints? (Choose two)
  • Sysmon file creation events (Event ID 11) showing large archive files (ZIP, RAR) created in temporary directories
  • PowerShell script block logging (Event ID 4104) showing commands that compress or encrypt files before transfer
  • Group Policy processing logs showing which policies were applied
  • BIOS boot event logs showing system startup times
  • Windows Update logs showing which patches were installed

Frequently Asked Questions

How many questions are on the exam?

The SecurityX CAS-005 exam contains 90 questions.

What is the passing score?

You need 75% to pass.

How long is the exam?

You have 165 minutes to complete the exam.

More CompTIA Practice Exams

Practice with realistic mock exams to prepare for your CompTIA certification.