How I Passed the CompTIA SecurityX (CAS-005) Exam

I sat for the CompTIA SecurityX exam on February 12th, 2026, and passed.
Here’s how I prepared, what worked, and what you should know if you’re considering it.
I started studying on December 20th, 2025, and booked my exam for February 12th, 2026, roughly seven and a half weeks from the first study session to exam day.
What is SecurityX, and Why Does Nobody Talk About It?
The CompTIA SecurityX (formerly CASP+) is CompTIA’s most advanced cybersecurity certification. It sits at the expert level, above Security+, above CySA+, above PenTest+.
And yet, if you ask most people in cybersecurity to name the top advanced certs, they’ll rattle off CISSP, CISM, maybe CCSP. Very few mention SecurityX (I know renaming bias doesn’t help).
That’s a shame, because the SecurityX is arguably the most technically demanding of the bunch. The CISSP and CISM are management-oriented certifications. They test your ability to think like a security executive. SecurityX is different. It wants you to think and do.
It combines deep technical knowledge with governance, risk management, and security architecture, which is the kind of thinking that happens when you’re the person who has to both design the solution and explain it.
The exam covers four domains:
Exam Format and Structure
The SecurityX (CAS-005) exam has a maximum of 90 questions delivered over 165 minutes.
You’ll face a mix of:
- Multiple-choice questions
- Performance-based questions (PBQs)
These PBQs test applied ability, not just theory.
Scoring is pass/fail only. There is no scaled score, e.g., 800/900. You either demonstrate competence across the domains or you don’t.
CompTIA recommends candidates have:
- 10 years of general hands-on IT experience
- At least 5 years of broad cybersecurity experience
That expectation shows in the exam depth. This is not an entry-level certification.
Exam Domains
The exam measures four domains:
1. Governance, Risk, and Compliance — 20%
Policy development, regulatory frameworks, enterprise risk strategy, and compliance alignment
2. Security Architecture — 27%
Infrastructure design, cloud and hybrid security, zero trust, enterprise architecture models
3. Security Engineering — 31%
Secure system design, cryptographic implementation, PKI, protocol engineering, control design
4. Security Operations — 22%
Incident response, threat intelligence, monitoring, detection engineering, forensics
Total: 100%
The Study Plan
Phase 1: The Course (Weeks 1–3)
I used Jason Dion’s SecurityX course on Udemy. The course has 25 sections, and I committed to one section per day. Each section runs between one hour and an hour and a half, with a few stretching to two hours.
At that pace, I finished the course in about three weeks, right around January 10th.
I’ll be honest, the course has some bloat.
There are lectures that repeat concepts you’ve already encountered, and some sections could be tighter. But the content coverage is solid, and Dion does a good job of mapping his material to the exam objectives.
Just know going in that not every minute will feel essential, and that’s okay. Take your notes, absorb what matters, and keep moving.
I took detailed notes throughout the course. Every section, every concept that felt important or unfamiliar, I wrote down.
The notes became the foundation of everything else I did.
Phase 2: Cross-Referencing and Deepening (Weeks 3–4)
After finishing the course, I pulled out the Packt Publishing SecurityX ebook and used it to cross-reference against my notes.
This wasn’t so much about reading a textbook cover to cover as it was about filling gaps. Where my notes from the Dion course felt thin, I’d check the Packt book for additional depth. Where the book covered something the course glossed over, I’d add it to my notes.
I also worked through the end-of-topic quizzes in the Packt book. These were useful for checking whether I actually understood a concept.
The real anchor through all of this was the exam objectives document. I printed it, I studied it, I tested myself against it. If you do nothing else, make sure you know those objectives inside and out. Every question on the exam maps back to them.
Phase 3: Practice Practice Practice! (Week 4-7)
I was done with study materials, and now I had to test myself.
This is where LLMs became my most powerful study partner.
I used Gemini to generate practice quizzes.
The process was simple: I shared the SecurityX exam objectives document with Gemini and prompted it to generate questions at varying difficulty levels.
It did this remarkably well. I could ask for 20 questions on Security Architecture at an intermediate level, or 15 hard questions on cryptographic implementations, and it would deliver relevant, well-structured questions with explanations. If you try this, here’s a prompt framework that worked for me:
“Based on the attached CompTIA SecurityX (CAS-005) exam objectives, generate [number] multiple-choice questions covering [domain/topic]. Set the difficulty to [beginner/intermediate/advanced]. Include four answer choices and a detailed explanation for each correct answer.”
I used ChatGPT differently.
Where Gemini was my quiz generator, ChatGPT was my tutor for weak spots. When I kept getting questions wrong on a particular topic, I’d go to ChatGPT and ask it to test me specifically on that area. I’d tell it where I was struggling, and it would probe those gaps until I could answer confidently.
This one-two punch of AI-assisted studying was, without exaggeration, the most effective part of my preparation.
The Practice App
This is where things got slightly interesting.
I wanted to practice in short, focused bursts that kept my recall sharp without needing a full study block.
I also wanted an easier way to stay engaged with the material no matter where I was or what I was doing, so I built a small web app: securityx.netlify.app.
It houses about 300 practice questions, organised into batches of 15 five-question sets designed for rapid drilling.
Something I could open on my phone while commuting, eating, or in idle pockets of the day.
Having those questions available on demand made a measurable difference.
It kept the material cognitively active even outside formal study sessions, reinforcing recall, pattern recognition, and exam instinct.
What the Exam Actually Felt Like
I had three performance-based questions (PBQs). One of them dropped me into a Linux virtual machine and asked me to identify and remediate a malicious process.
If you’re not comfortable at the Linux command line, this will hurt you. Know your process management commands — ps, top, kill, systemctl.
Know how to use man pages and the –help flag to navigate commands you might not have memorised.
The exam isn’t asking you to be a Linux sysadmin, but it expects you to be functional.
The curriculum also covers scripting languages like Python, PowerShell, and Bash.
You don’t need to write scripts from scratch, but you absolutely need to be able to read them. You need to look at a Python snippet and understand what it’s doing.
You need to read a PowerShell one-liner and know what it’s querying. Same with configuration files and log outputs.
The exam will put something in front of you and ask you to interpret it.
There’s also a section on AI governance. It’s not deeply technical. It covers the governance and policy aspects like ethical AI use, bias considerations, and regulatory frameworks.
And I think that’s exactly right for where we are right now. The security community needs to understand AI governance at a policy level before we can meaningfully secure AI systems at a technical level.
Honestly? I found the exam relatively easy. Not because the content is simple — it isn’t — but because my preparation was thorough.
By the time I sat down on exam day, I had seen enough variations of every concept that very little caught me off guard.
The practice questions had trained my brain to recognise patterns, and even on questions where I wasn’t 100% certain, I could make educated guesses with confidence.
Things That Worked
Study at least one hour a day. This was non-negotiable for me. Consistency builds rhythm. Your brain starts to anticipate the study session, and the material begins to compound. Some days I did more, but I never did less than an hour.
Track your blind spots. Every time I got a question wrong, I logged the topic. Over time, patterns emerged in specific areas where my understanding was shallow. I attacked those systematically. By exam day, my former blind spots were some of my strongest areas.
Use the exam objectives as your Bible. Every question on the exam maps to an objective. If you can confidently speak to every line item in that document, you’re ready.
Build and break things. I was working on a couple of lab environments while studying, and some of the SecurityX topics mapped directly to what I was building. There’s no substitute for hands-on implementation.
Use AI aggressively for practice. This isn’t 2019. The tools are here. Use them. Generate hundreds of practice questions. Have LLMs tutor you on your weak spots. Build your own quizzes. The more reps you get, the better prepared you’ll be.
If you’re thinking about taking the SecurityX, do it. Prepare well, use every tool at your disposal, and respect the breadth of the curriculum. It’s a certification that will genuinely make you better at your job.
Good luck.
— David