CompTIA SecurityX (CAS-005) Practice Test

152 questions available

Build your confidence for CompTIA SecurityX (CAS-005). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
90 Exam questions
2 hours 45 minutes Time Limit
Your practice
152 Practice questions
2 hours 32 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 100-900 Published passing score for this certification.
Explore exam topics Official objectives from CompTIA
CompTIA152 practice questionsBank updated 2026-07-24
Blueprint verifiedChecked against CompTIA official objectivesMetadata verified 2026-09-17How we verify

Exam overview and details

The CompTIA Security+ (SY0-701) certification is a globally recognized, vendor-neutral credential that validates the foundational cybersecurity skills required for core security functions and an IT security career. It establishes the baseline knowledge necessary for roles such as Security Analyst, Systems Administrator, and Network Administrator, focusing on hands-on practical skills to identify, assess, and respond to security incidents. The certification covers the most current principles for risk management, threat mitigation, and security architecture, ensuring professionals are equipped to address today's complex threat landscape. Earning Security+ demonstrates a professional's competency in key areas like network security, compliance, operational security, and threats/vulnerabilities, making it a critical first step for those entering the cybersecurity field and a requirement for many Department of Defense (DoD) positions. It serves as a springboard to intermediate-level cybersecurity jobs and more advanced certifications.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Security architecture

A government agency's security architect is planning the transition to post-quantum TLS for high-security web services that will be operational beyond 2030. NIST recommends a hybrid classical+PQC approach during the transition period. Which hybrid key exchange approach in TLS 1.3 is being standardized to provide both classical and post-quantum security simultaneously, and what is the security rationale for the hybrid approach?

Security engineering

A brokerage's endpoint telemetry shows browser-based exploitation attempts against analysts who open untrusted research links. The endpoints are fully patched, but the business requires analysts to view hostile sites. The CISO wants to reduce exploit impact without blocking research. Which control best fits?

Security architecture

A defense contractor is replacing static roles in an engineering portal. Access decisions must consider clearance, project assignment, device compliance, export-control citizenship, and time-limited need-to-know. Audit wants one place to evaluate policy while applications enforce the result consistently. Which design best fits?

Governance_Risk_Compliance

A DevSecOps team is hardening their software supply chain following a build-system compromise similar to the SolarWinds attack. They want to implement the SLSA (Supply-chain Levels for Software Artifacts) framework to establish build provenance. The team's current CI/CD pipeline uses GitHub Actions and builds Docker container images. They want to achieve at minimum SLSA Level 3 for all production container images. Which combination of requirements MUST the team implement to satisfy SLSA Level 3?

Security architecture

An enterprise DLP solution is configured to prevent exfiltration of PII, PCI cardholder data, and proprietary trade secrets. The DLP policy uses content inspection with regex patterns for credit card numbers and SSNs. Security analysts observe that a large volume of sensitive data is being transmitted via HTTPS to a cloud file-sharing service without triggering DLP alerts. Forensic analysis reveals the data was compressed with 7-Zip before upload. Which DLP evasion technique is demonstrated, and which DLP capability is required to detect it?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

CompTIA Security+ is more than a certification; it is an industry-standard benchmark for cybersecurity proficiency and a critical differentiator in the job market. It validates to employers that you possess the essential, hands-on skills to secure networks, manage risk, and respond to incidents-skills that are in high demand globally. Holding this certification significantly enhances career prospects, often leading to higher earning potential and qualifying candidates for roles that require DoD 8570 compliance. Its vendor-neutral nature ensures your knowledge is foundational and adaptable, providing recognition that is respected across all sectors of the IT industry and establishing a credible foundation for long-term career advancement in cybersecurity.

These are the backgrounds the certifying body suggests. Check the vendor's own page for anything it formally requires.

Your Path Forward

You are here CompTIA SecurityX (CAS-005) Practice Test Step 4 of 4 – Expert
CompTIA Cybersecurity Ladder

What this exam covers

Use the published domain weights to plan your study. Practice results do not predict your certification exam score.

01Security engineering

31%

Presents security engineering concepts carrying a 31.0 percent weight, including automation, vulnerability management, and advanced cryptography designed to secure modern systems against evolving threats and infrastructure vulnerabilities encountered in professional environments.

Topics

  • Automation
  • Vulnerability management
  • Advanced cryptography
  • Cryptographic use cases
  • Cryptographic techniques

Learning objectives

  • Automation: scripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation
  • Vulnerability management: scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS)
  • Advanced cryptography: PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration
  • Cryptographic use cases: data at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication
  • Cryptographic techniques: tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography

02Security architecture

27%

Focuses on security architecture with a 27.0 percent weight, addressing cloud capabilities, cloud data security, and tailored control strategies for complex enterprise environments to ensure strong protection of digital assets across systems.

Topics

  • Cloud capabilities
  • Cloud data security
  • Cloud control strategies
  • Network architecture
  • Security boundaries
  • Deperimeterization
  • Zero trust concepts

Learning objectives

  • Cloud capabilities: CASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads
  • Cloud data security: data exposure, leakage, remanence, insecure storage, and encryption keys
  • Cloud control strategies: proactive, detective, and preventative controls; customer-to-cloud connectivity, service integration, and continuous authorization
  • Network architecture: segmentation, microsegmentation, VPN, always-on VPN, and API integration
  • Security boundaries: asset identification, management, attestation, data perimeters, and secure zones
  • Deperimeterization: SASE, SD-WAN, and software-defined networking
  • Zero trust concepts: defining subject-object relationships

03Security operations

22%

Involves security operations carrying a 22.0 percent weight, concentrating on monitoring and data analysis, vulnerabilities and attack surfaces, alongside proactive threat hunting methodologies utilized for effective incident detection and response.

Topics

  • Monitoring and data analysis
  • Vulnerabilities and attack surface
  • Threat hunting
  • Incident response

Learning objectives

  • Monitoring and data analysis: SIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users)
  • Vulnerabilities and attack surface: injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth
  • Threat hunting: internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort)
  • Incident response: malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis

04Governance, risk, and compliance

20%

Covers governance, risk, and compliance with a 20.0 percent weight, focusing heavily on program management, frameworks, and vital security program documentation required for organizational security compliance and standard operations.

Topics

  • Security program documentation
  • Program management
  • Frameworks
  • Configuration management
  • GRC tools
  • Data governance
  • Risk management
  • Threat modeling
  • Attack surface
  • Compliance strategies
  • Security frameworks

Learning objectives

  • Security program documentation: policies, procedures, standards, and guidelines
  • Program management: training (phishing, security, privacy), communication, reporting, and RACI matrix
  • Frameworks: COBIT, ITIL, etc
  • Configuration management: asset life cycle, CMDB, and inventory
  • GRC tools: mapping, automation, and compliance tracking
  • Data governance: production, development, testing, and QA
  • Risk management: impact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability
  • Threat modeling: actor characteristics, attack patterns, and frameworks (ATT&CK, CAPEC, STRIDE)
  • Attack surface: architecture reviews, data flows, and trust boundaries
  • Compliance strategies: industry-specific standards (PCI DSS, ISO/IEC 27000)
  • Security frameworks: NIST, CSF, CSA, and others

Exam Details CAS-005 | $509 USD | 2 hours 45 minutes

Exam Code CAS-005
Vendor CompTIA
Exam Cost $509 USD
Passing Score 100-900
Time Limit 2 hours 45 minutes
Exam questions 90
Question TypesMultiple Choice (single), Multiple Choice (multiple), Performance-Based
Retake Policy No waiting period required before first retake. After the second failed attempt, candidates must wait 14 calendar days before any subsequent attempt. No limit on total attempts.
Exam Format Linear
Online Proctoring Available
Available In
EnglishJapanesePortugueseSimplified Chinese

Frequently Asked Questions

What are the prerequisites for taking the CompTIA Security+ exam?

How does Security+ help with DoD 8570/8140 compliance?

What is the difference between Security+ and a Certified Ethical Hacker (CEH) certification?

How long is the Security+ certification valid, and how do I renew it?

What types of questions are on the Security+ SY0-701 exam?