CASP+ (CompTIA Advanced Security Practitioner)
CompTIA
Complete guide to passing the CASP+ (CompTIA Advanced Security Practitioner) exam on your first attempt.
$494
~19%
3 years
Global
CompTIA
$110k-$160k
Are you ready for CASP+ (CompTIA Advanced Security Practitioner)?
Loading quiz...
Complete Overview
CASP+ is CompTIA's advanced practitioner-level security certification, and since 17 December 2024 CompTIA has sold it under the name SecurityX with the exam code CAS-005. It is written for senior technical staff who want to stay hands-on in security architecture and engineering rather than move into programme management, and CompTIA recommends a minimum of 10 years of general hands-on IT experience including 5 years of hands-on security before attempting it. CompTIA publishes no voucher price on the SecurityX certification page, and store.comptia.org product links currently redirect to the certification index, so the price is only visible at checkout. Budget from the store, not from a figure quoted in a study guide.
The exam is a maximum of 90 questions in a maximum of 165 minutes. CompTIA describes the item mix as multiple-choice and performance-based questions, the latter putting you into a scenario that requires a working configuration or analysis rather than a selected option. CompTIA reports the result as pass or fail with no scaled score, which is unusual across its portfolio: Security+ and Network+ both return a number on a 100 to 900 scale, and SecurityX returns neither a number nor a domain breakdown.
The CAS-005 blueprint has four domains: Security Engineering at 31 percent, Security Architecture at 27 percent, Security Operations at 22 percent, and Governance, Risk and Compliance at 20 percent. Engineering and architecture together account for 58 percent of the exam, which is the clearest signal of what CompTIA changed in this version. Content that did not exist in earlier CASP+ versions includes post-quantum cryptography, homomorphic encryption, zero trust subject-object relationships, SASE and SD-WAN deperimeterization, infrastructure as code, and AI-influenced attack surface analysis.
CompTIA names Network+, Security+, CySA+, Cloud+ and PenTest+ as the knowledge base the exam assumes, though none of them are enforced as a registration prerequisite. Nobody checks your experience before you book. The exam checks it for you through performance-based items that assume you have already built the thing being asked about.
SecurityX holds ANAB ISO/IEC 17024 personnel certification accreditation, granted 13 December 2011 and current through 14 March 2028, and CompTIA lists it against NICE and DoD 8140 work roles including security architect, systems requirements planner, security control assessor and research and development specialist, which is why it appears in federal and defence contractor job requirements. The certification is valid for three years and renews on 75 continuing education units plus a CE fee of USD 150 for the whole three-year cycle, the same band as Security+. The rebrand from CASP+ to SecurityX did not affect the certification status of existing holders or the continuing education programme.
CAS-005 is the only version CompTIA now lists for SecurityX; CAS-004 has retired. CompTIA estimates retirement for CAS-005 in 2027, on its usual pattern of about three years after launch. If you are studying from material that lists five domains including Research, Development and Collaboration, you are reading a previous version of the blueprint.
Why Get CASP+ (CompTIA Advanced Security Practitioner) Certified?
CompTIA lists SecurityX against NICE and DoD 8140 work roles including security architect, systems requirements planner and security control assessor, which makes it a qualifying credential for federal and defence contractor positions.
CAS-005 launched on 17 December 2024 and CompTIA estimates retirement in 2027, on its usual three-year pattern, so a pass now carries a full three-year certification cycle before the next version forces a decision.
Security Engineering carries 31 percent of the exam and covers post-quantum cryptography, homomorphic encryption, key stretching and infrastructure as code, which is more forward-dated cryptography content than any other vendor-neutral certification at this level.
CompTIA designed SecurityX for technical professionals who want to stay immersed in technology rather than manage a cybersecurity programme, which distinguishes it from CISSP and CISM.
Renewal costs USD 150 in CE fees for the whole three-year cycle plus 75 CEUs, and passing SecurityX also renews lower CompTIA certifications you already hold.
The certification carries ANAB ISO/IEC 17024 personnel accreditation, current through 14 March 2028, which is what public sector procurement frameworks check for.
Performance-based simulations mean the credential evidences that you can configure and analyse, not only recognise the right answer among four.
Exam Format & Structure
Duration
Maximum of 165 minutes
Questions
Maximum of 90 questions
Passing Score
Pass or fail only. CompTIA does not report a scaled score for SecurityX and does not publish a numeric cut score.
Question Types
- Multiple choice
- Performance-based questions requiring analysis or configuration in a scenario
Delivery Method
Pearson VUE test centre or Pearson OnVUE online proctored delivery. CompTIA structures its exams as a single session with no scheduled breaks. OnVUE requires a private room, a single screen, at least 6 Mbps download and 2 Mbps upload, and is unavailable to candidates in Cuba, Iran, North Korea, Sudan, Syria, Russia, Belarus and certain Ukrainian territories.
Exam Domains & Topics
The largest domain in CAS-005 and the one that changed most from previous CASP+ versions. It covers automation of security processes, vulnerability management workflows, and advanced cryptography including algorithms and use cases that were absent from the CAS-004 blueprint. Expect performance-based items that ask you to select and justify a cryptographic approach for a stated constraint.
Key Topics to Master:
- Automation with scripting languages and infrastructure as code
- Vulnerability management, scanning workflows and SCAP standards
- Advanced cryptography: post-quantum cryptography, key stretching, homomorphic encryption
- Cryptographic use cases for data at rest, data in transit and data in use
- Cryptographic techniques including tokenization and digital signatures
- Key management, rotation and escrow at enterprise scale
- Secure configuration and hardening pipelines
- Integration of engineering controls into existing enterprise systems
Covers how an enterprise estate is put together across cloud and on-premises boundaries. Cloud capability controls, network segmentation and microsegmentation, security boundaries and asset management, and the deperimeterization technologies that replace a traditional edge all appear here, along with the zero trust model expressed as subject-object relationships.
Key Topics to Master:
- Cloud capabilities including CASB, shadow IT detection and CI/CD pipeline security
- Cloud data security: exposure, leakage and encryption key management
- Proactive, detective and preventative cloud control strategies
- Network architecture with segmentation and microsegmentation
- Security boundaries and enterprise asset management
- Deperimeterization with SASE and SD-WAN
- Zero trust concepts and defining subject-object relationships
- Architecture decisions driven by regulatory and availability constraints
Covers running the environment once it is built: monitoring and analysing telemetry, mitigating exposure on a live attack surface, hunting for activity that detection did not catch, and responding when something lands. Incident response items reach into malware analysis and root cause analysis rather than stopping at the containment checklist.
Key Topics to Master:
- Monitoring and data analysis with SIEM and behavioural baselines
- Attack surface mitigation strategies for known vulnerabilities
- Threat hunting using internal and external threat intelligence
- Incident response process and playbook design
- Malware analysis techniques applied to a live incident
- Root cause analysis and post-incident improvement
- Detection engineering and alert tuning
- Forensic evidence handling in an enterprise environment
Covers the documentation and process layer: policy hierarchy, programme management, configuration and data governance, risk assessment including third parties, threat modelling with named frameworks, and compliance against specific regulatory standards. It is the domain that technical candidates most often treat as filler and then lose marks on.
Key Topics to Master:
- Security programme documentation: policies, procedures, standards and guidelines
- Programme management with training, communication, reporting and RACI matrices
- Frameworks including COBIT and ITIL
- Configuration management, asset lifecycle and inventory systems
- GRC tooling for control mapping, automation and compliance tracking
- Data governance across production, development, testing and QA environments
- Risk management, impact analysis and third-party risk assessment
- Threat modelling with MITRE ATT&CK, CAPEC and STRIDE
- Compliance with PCI DSS, ISO/IEC 27000 series, NIST CSF and CSA guidance
Recommended Study Plan
- 1Download the CAS-005 exam objectives PDF from comptia.org and confirm you are not studying CAS-004 material with five domains
- 2Score yourself honestly against every objective bullet and mark each as confident, shaky or unseen
- 3Confirm your foundation: CompTIA assumes Network+, Security+, CySA+, Cloud+ and PenTest+ level knowledge
- 4Decide between a Pearson VUE test centre and Pearson OnVUE online delivery, since the rules differ substantially
- 5Book a target exam date 10 weeks out to force pace
- 1Learn the policy hierarchy precisely: policy, standard, procedure, guideline, and which is mandatory
- 2Build a RACI matrix for a real security programme activity at your own organisation
- 3Read the NIST Cybersecurity Framework core functions and the CSA guidance structure
- 4Study PCI DSS scope reduction and the ISO/IEC 27000 series structure
- 5Practise 30 GRC objective questions and log every miss with the reasoning
- 1Work through MITRE ATT&CK tactics and techniques and navigate the matrix without a cheat sheet
- 2Apply STRIDE to one application and CAPEC to one attack path, then write up both
- 3Study third-party risk assessment and what evidence a vendor questionnaire can and cannot prove
- 4Learn impact analysis terminology: SLE, ALE, ARO and how each drives a control decision
- 5Map data governance requirements across production, development, testing and QA environments
- 1Study CASB deployment modes and what shadow IT detection actually sees
- 2Build a CI/CD pipeline in a free-tier account and add a secrets scanning and SAST stage
- 3Learn the proactive, detective and preventative control split as CompTIA frames it
- 4Study cloud data exposure and leakage paths and the key management options for each
- 5Complete a CertMaster Labs cloud security lab or equivalent hands-on exercise
- 1Diagram segmentation and microsegmentation for a three-tier application and defend each boundary
- 2Study zero trust as subject-object relationships, which is the framing CompTIA uses in the objectives
- 3Learn SASE and SD-WAN components and which traditional control each replaces
- 4Practise asset management and boundary definition for a hybrid estate
- 5Complete a full architecture design exercise from a written requirement set
- 1Study post-quantum cryptography: what the threat model is and which algorithm families are candidates
- 2Learn homomorphic encryption, what it enables for data in use, and its practical limits
- 3Study key stretching functions and when each is appropriate
- 4Build a decision table mapping data at rest, data in transit and data in use to a technique
- 5Practise distinguishing tokenization, digital signatures, hashing and encryption by the property each provides
- 1Write infrastructure as code that provisions a hardened resource and review what the code enforces
- 2Study SCAP components and how automated compliance checking works end to end
- 3Build a vulnerability management workflow from discovery through remediation verification
- 4Practise scripting a repetitive security task in Python or PowerShell
- 5Work through the engineering objective bullets and mark any still unseen
- 1Build behavioural baselines from log data and identify what deviation looks like
- 2Practise threat hunting with a hypothesis, a data source and a written result
- 3Study malware analysis at the level SecurityX asks for: static triage, dynamic indicators, containment implications
- 4Work a full incident response scenario from detection through root cause analysis
- 5Practise 40 operations questions under time pressure
- 1Work every performance-based item in CertMaster Practice or an equivalent product until the interaction style is routine
- 2Time yourself: with a maximum of 90 questions in 165 minutes, the average is under two minutes per item and simulations run long
- 3Rehearse the tactic of skipping simulations on first pass and returning to them once the multiple-choice items are banked
- 4Re-drill your weakest domain from the objective checklist
- 5Sit a full-length timed practice exam
- 1Sit a second full-length timed practice exam and review every miss against the objectives PDF
- 2Read the CompTIA candidate ID policy and confirm both IDs are unexpired with names matching your registration exactly
- 3If testing with OnVUE, run the system test on the exact device and network you will use
- 4Clear your testing room, since OnVUE requires a private quiet space with a clear desk and terminates sessions when another person or a pet appears
- 5Plan for a single session with no scheduled break and use the restroom before check-in
Ready to pass CASP+ (CompTIA Advanced Security Practitioner)?
Get 500+ practice questions, video walkthroughs, and a pass guarantee.
Best Study Resources
CompTIA SecurityX (CAS-005) exam objectives
Official blueprintThe four-domain blueprint with weights, the exam-detail block giving 90 questions, 165 minutes and pass/fail scoring, and every skill bullet CompTIA can test. Use it as your gap-analysis checklist.
Free
CompTIA CertMaster Learn for SecurityX
Self-paced courseCompTIA's own e-learning product mapped bullet by bullet to the CAS-005 objectives, with performance-based practice built in.
Paid, sold individually or in bundles
CompTIA CertMaster Labs for SecurityX
Hands-on labsBrowser-delivered labs that mirror the performance-based item style. The closest available practice to the simulations you will see on exam day.
Paid, sold individually or in bundles
CompTIA CertMaster Practice for SecurityX
Practice examAdaptive question bank with objective-level feedback. Use it to find blind spots rather than to memorise items.
Paid, sold individually or in bundles
SecurityX complete bundle with retake assurance
BundleCombines an exam voucher plus a retake with CertMaster products. Worth pricing against buying the voucher alone given the exam's difficulty.
Sold in the CompTIA Store, price varies
MITRE ATT&CK
FrameworkNamed directly in the threat modelling objective. Navigate the enterprise matrix, and know how ATT&CK differs from CAPEC in what it catalogues.
Free
NIST post-quantum cryptography standards
StandardBackground for the advanced cryptography objective, which names post-quantum cryptography explicitly. Read the algorithm selections and the migration guidance rather than the mathematics.
Free
CompTIA candidate ID policy and online-proctored exam guidelines
Official policyDefines the two-ID requirement, name matching, and the OnVUE workspace rules including the digital whiteboard and the no-breaks position.
Free
CompTIA continuing education renewal fees
Official policyConfirms that SecurityX sits in the USD 150 per three-year-period CE fee band and that 75 CEUs are required to renew.
Free
Cloud Security Alliance guidance and Cloud Controls Matrix
ReferenceCSA is named in the security frameworks objective. Use the Cloud Controls Matrix for the architecture domain's cloud control strategy content.
Free
Common Mistakes to Avoid
Studying CAS-004 material. CAS-004 has retired and CompTIA lists only V5, while older guides list five domains including Research, Development and Collaboration, which no longer exist.
Check the domain list on the front of any book or course before you start. If it does not read Governance Risk and Compliance 20, Security Architecture 27, Security Engineering 31, Security Operations 22, it is the wrong version.
Skipping the post-quantum cryptography and homomorphic encryption content because it feels academic. Advanced cryptography sits inside the 31 percent Security Engineering domain and is named explicitly in the objectives.
Learn what problem each technique solves rather than the mathematics. Post-quantum cryptography answers the harvest-now-decrypt-later threat; homomorphic encryption enables computation on data in use. Exam items test the selection decision.
Running out of time because performance-based simulations were attempted in order. A single simulation can eat a disproportionate share of a 165-minute budget that has to cover up to 90 items.
Skip simulations on the first pass, bank every multiple-choice item you can answer quickly, then return with a known remaining time budget. The item review screen makes this straightforward.
Expecting a score report to diagnose a failure. CompTIA reports SecurityX as pass or fail with no scaled score and no domain breakdown.
Diagnose before the exam, not after. Use CertMaster Practice objective-level feedback to identify weak areas while you can still act on the data, because a fail gives you nothing to work from.
Treating the Governance, Risk and Compliance domain as common sense. Twenty percent of the exam sits there, and it tests specific vocabulary such as the difference between a standard and a guideline.
Memorise the documentation hierarchy, the named frameworks COBIT and ITIL, and what a RACI matrix assigns. These are recall items and they are the cheapest marks on the exam.
Booking the exam without meeting the assumed baseline. CompTIA recommends 10 years of IT experience including 5 years in security, plus Network+, Security+, CySA+, Cloud+ and PenTest+ level knowledge.
None of this is enforced at registration, so audit yourself. If you cannot read a packet capture, script an automation task and reason about cloud key management, close those gaps before booking rather than discovering them in a simulation.
Choosing OnVUE online delivery without preparing the room, then losing the session. CompTIA terminates exams when another person or a pet appears on camera.
Test in a private, quiet, well-lit room with a clear desk and a door you control. Run the OnVUE system test on the same device and network beforehand, and confirm at least 6 Mbps download and 2 Mbps upload.
Planning to take a break mid-exam. CompTIA structures its exams as a single session with no scheduled breaks, and for online delivery breaks are only permitted as an approved accommodation at a test centre.
Use the restroom before check-in and manage fluid intake. Treat 165 minutes as continuous work and pace accordingly.
Bringing a US military ID to an online proctored session. It is accepted for in-person testing but not for OnVUE.
Bring two original unexpired IDs whose first and last names match your registration exactly. For OnVUE use a passport, driver's licence, national identification card or alien registration card as the primary document.
Exam Day Tips
- 1
Bring two original, valid, unexpired identification documents. The primary must be government-issued with a photograph, and the secondary must carry at least your name and signature or name and photograph.
- 2
Check the name spelling on both documents against your CompTIA registration. CompTIA requires the first and last name used to register to match exactly on both IDs presented on test day.
- 3
If you booked OnVUE, do not plan to use a US military ID, since CompTIA excludes it for online proctored exams even though it is accepted at a test centre.
- 4
Expect to be photographed at a test centre before testing, and to be recorded through your webcam for the full session if you test online.
- 5
Clear the desk completely for online delivery. Only the exam computer and pre-approved items are permitted, and books, notes, papers, food and drink must be beyond arm's reach.
- 6
There is no physical scratch paper for online testing. Use the built-in digital whiteboard, and practise with it beforehand so you are not learning the interface during a simulation.
- 7
Plan for a single continuous session. CompTIA structures its exams without scheduled breaks, and online breaks are permitted only as an approved accommodation at a test centre.
- 8
Budget the clock against 90 items in 165 minutes, roughly 110 seconds each. Move past every performance-based simulation on the first pass and return to them with your remaining time known.
- 9
Expect a pass or fail result with no number and no domain breakdown, so there is nothing to analyse afterwards. If you fail, CompTIA allows an immediate second attempt, then requires 14 calendar days before a third or any subsequent attempt.
Career Paths & Salary Ranges
Security architect
Designs segmentation, zero trust boundaries and cloud control strategies for an enterprise estate. The 27 percent Security Architecture domain is the direct preparation, including SASE, SD-WAN and CASB decision-making.
$110k-$160k
Senior security engineer
Builds and automates the controls: infrastructure as code, cryptographic implementation, SCAP-driven compliance checking and vulnerability management pipelines. Security Engineering is the largest domain at 31 percent.
$110k-$160k
Security operations lead
Owns detection engineering, threat hunting and incident response including root cause analysis. The 22 percent operations domain covers SIEM analysis, behavioural baselines and malware triage.
$110k-$160k
Cybersecurity risk and compliance manager
Runs policy, third-party risk and compliance evidence against PCI DSS, ISO/IEC 27000 and NIST CSF. The 20 percent GRC domain plus SecurityX's ISO/IEC 17024 accreditation supports the role in regulated environments.
$110k-$160k
Federal or defence contractor security specialist
CompTIA lists SecurityX against NICE and DoD 8140 work roles including security architect, systems requirements planner, security control assessor and research and development specialist, which makes it a qualifying credential for positions that require an approved certification for the work role.
$110k-$160k
Prerequisites & Requirements
- There are no enforced prerequisites. CompTIA does not verify experience or prior certifications at registration.
- CompTIA recommends a minimum of 10 years of general hands-on IT experience, including at least 5 years of hands-on security experience.
- CompTIA names Network+, Security+, CySA+, Cloud+ and PenTest+ as the certifications whose knowledge the exam assumes, or equivalent knowledge gained through work.
- Practical ability with scripting and infrastructure as code is assumed by the Security Engineering domain, which carries 31 percent of the exam.
- The English-language CAS-004 exam has retired, so CAS-005 is the current version to register for.
Frequently Asked Questions
Is CASP+ the same as SecurityX?
Yes. CompTIA rebranded CASP+ as SecurityX on 17 December 2024, at the same time as it released exam version 5 with the code CAS-005. The rebrand did not affect the certification status of existing CASP+ holders or the continuing education programme, so a valid CASP+ remains valid and renews the same way. Job postings still use both names, and the exam you register for today is CAS-005.
How many questions are on the SecurityX exam and how long is it?
A maximum of 90 questions in a maximum of 165 minutes. That averages under two minutes per item. CompTIA describes the mix as multiple-choice and performance-based questions, and the performance-based items take considerably longer than the average, which is why pacing matters more here than on Security+.
What is the passing score for SecurityX?
CompTIA reports SecurityX as pass or fail only and does not publish a scaled score or a numeric cut score. This differs from Security+ and Network+, which return a score on a 100 to 900 scale. You also do not receive a domain-level breakdown, so a failed attempt gives you no diagnostic data to work from.
What are the SecurityX CAS-005 domains and weights?
Four domains: Security Engineering at 31 percent, Security Architecture at 27 percent, Security Operations at 22 percent, and Governance, Risk and Compliance at 20 percent. If a study resource lists five domains including Research, Development and Collaboration, it covers the retired CAS-004 blueprint rather than the current exam.
What happens if I fail the SecurityX exam?
CompTIA imposes no waiting period between the first and second attempt, so you may rebook immediately. Before a third attempt or any subsequent attempt you must wait at least 14 calendar days from the date of your last attempt. Each attempt requires a new voucher. CompTIA states these requirements cannot be waived, and an exam taken in violation of the retake policy is invalidated with a possible suspension.
How much does the SecurityX exam cost?
CompTIA sells the CAS-005 voucher through its own store rather than publishing a price on the certification page, so check store.comptia.org for the current figure before budgeting. CompTIA also sells bundles that pair a voucher and a retake with CertMaster Practice, or with CertMaster Perform, Practice and Labs, which is worth pricing against the voucher alone given the exam's difficulty.
What ID do I need for the SecurityX exam?
Two original, valid, unexpired IDs. The primary must be government-issued with your name and a recent recognisable photograph, such as a passport, driver's licence, national or state identification card, or alien registration card. The secondary must contain at least your name and signature or your name and a recent photograph. The first and last names you registered with must match both documents exactly. Photocopies and digital copies are not accepted, and US military ID is accepted only for in-person testing.
Can I take SecurityX online at home?
Yes, through Pearson OnVUE. You need a private, quiet, well-lit room that is not a public space or a bathroom, a completely clear desk, and a device meeting the minimum specification with a webcam, a microphone and at least 6 Mbps download and 2 Mbps upload. CompTIA terminates sessions if another person or a pet becomes visible, if you appear on camera without being fully dressed, or if you do not follow proctor instructions about the space.
Can I use scratch paper or a calculator on the SecurityX exam?
For online proctored delivery, no physical note-taking materials are permitted and you use the built-in digital whiteboard instead. Only your exam computer and pre-approved items may be on the desk. Practise with the whiteboard before exam day so the interface is familiar when you need to sketch a segmentation diagram during a simulation.
Are there breaks during the SecurityX exam?
No. CompTIA structures its exams to be completed in a single session with no scheduled breaks. For online delivery, breaks are permitted only with prior approval as an accommodation, and only at a test centre. CompTIA advises using the restroom before check-in, which is practical advice for a 165-minute sitting.
How long is SecurityX valid and how do I renew it?
Three years. Renewal requires 75 continuing education units earned within the three-year cycle plus a CE fee of USD 150 for the period, which is the band SecurityX sits in alongside Network+, Security+, CySA+, PenTest+ and Cloud+. The fee is a single three-year charge rather than an annual one, and can be paid with CE tokens. Passing a higher or current CompTIA exam is an alternative renewal route.
Does passing SecurityX renew my other CompTIA certifications?
Yes, CompTIA's continuing education programme allows a higher-level certification to renew lower ones in the same pathway, which is why candidates who hold Security+, CySA+ and PenTest+ often take SecurityX partly for renewal efficiency. Confirm the current renewal mapping in your CompTIA account before relying on it, since CompTIA updates the pathway as certifications are added and retired.
How does SecurityX compare to CISSP?
CompTIA positions SecurityX for technical professionals who want to stay immersed in technology rather than manage a cybersecurity programme, while CISSP is a management-oriented credential with a five-year verified experience requirement and an endorsement step. SecurityX enforces no experience requirement and tests through performance-based simulations. Many senior practitioners hold both, using SecurityX to evidence hands-on architecture and engineering depth and CISSP for programme leadership roles.
How does SecurityX compare to CompTIA Security+?
Security+ is an early-career certification with a 90-minute exam and a scaled score. SecurityX runs 165 minutes, reports only pass or fail, assumes 10 years of IT experience including 5 in security, and devotes 58 percent of its content to architecture and engineering. Security+ asks you to identify a control; SecurityX asks you to select between competing controls under a stated constraint and then configure or analyse one.
What is the SecurityX pass rate?
CompTIA does not publish pass rates for any of its certifications. Low figures circulate for CASP+ in study communities, including estimates near 19 percent, but these are self-reported and not vendor data. What CompTIA does publish is the recommended experience level, and the gap between that recommendation and the average candidate's background explains most reported failures.
Does SecurityX count for DoD 8140?
Yes. SecurityX carries ANAB ISO/IEC 17024 personnel certification accreditation, current through 14 March 2028, and CompTIA lists it against NICE and DoD 8140 work roles including security architect, systems requirements planner, security control assessor and research and development specialist. Check the current DoD qualification matrix for the specific work role and proficiency level you need, since role mappings are revised periodically.
Are accommodations available for the SecurityX exam?
Yes. CompTIA operates a testing accommodations process, and its online-proctored guidelines note that breaks are permitted only with prior approval as an accommodation and only at a test centre. Request accommodations through CompTIA before scheduling with Pearson VUE, since approval has to be in place before the appointment is booked.
How long should I study for SecurityX?
The plan on this page runs 10 weeks at 10 to 14 hours a week, which suits a candidate already working in security architecture or engineering. Candidates without cloud and automation exposure should add time to weeks 4 through 7, since Security Architecture and Security Engineering together account for 58 percent of the exam and both include content that did not appear in earlier CASP+ versions.
Pass CASP+ (CompTIA Advanced Security Practitioner), Guaranteed
94% pass rate on first attempt
One-time • Lifetime access