CompTIA credentialCER0408

SecurityX

Exam code: CAS-005
Official provider page
CompTIA
Credential
Certification
Level
Certification
Exam duration
165 min

credential overview

About this credential

Advanced cybersecurity certification for security architects and senior security engineers covering governance, risk and compliance, security architecture, engineering, operations, and complex secure solutions.

Who this is for

Security architects, senior security engineers, and highly experienced cybersecurity professionals.

Assessment

Exam details

CAS-005
Duration
165 min

English, other languages TBD

Exam blueprint

Skills measured

Governance, risk, and compliance (20%)11 topics
  • Maintain security program documentation including policies, procedures, standards, and guidelines.
  • Manage training, communication, reporting, and RACI structures.
  • Use frameworks such as COBIT and ITIL.
  • Manage configuration, asset lifecycle, CMDB, and inventory.
  • Use GRC tools for mapping, automation, and compliance tracking.
  • Apply data governance across production, development, testing, and QA.
  • Perform quantitative and qualitative risk management and third-party risk assessment.
  • Perform threat modeling using frameworks such as ATT&CK, CAPEC, and STRIDE.
  • Analyze attack surface through architecture reviews, data flows, and trust boundaries.
  • Apply industry compliance strategies such as PCI DSS and ISO/IEC 27000.
  • Use security frameworks such as NIST, CSF, and CSA.
Security architecture (27%)6 topics
  • Apply cloud capabilities including CASB, shadow IT detection, shared responsibility, CI/CD, Terraform, Ansible, containers, orchestration, and serverless.
  • Address cloud data exposure, leakage, remanence, insecure storage, and encryption-key risks.
  • Apply cloud control strategies and secure customer-to-cloud connectivity and service integration.
  • Design segmented network architecture, microsegmentation, VPN, always-on VPN, and API integration.
  • Define security boundaries, asset attestation, data perimeters, and secure zones.
  • Apply SASE, SD-WAN, software-defined networking, and zero-trust concepts.
Security engineering (31%)5 topics
  • Use automation, scripting, event triggers, IaC, cloud APIs, generative AI, containers, patching, SOAR, and workflow automation.
  • Perform vulnerability scanning and reporting using SCAP-related standards.
  • Apply advanced cryptography including PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration.
  • Apply cryptography to data at rest, in transit, and in use, secure email, blockchain, privacy, compliance, and certificate authentication.
  • Use tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography.
Security operations (22%)4 topics
  • Use SIEM, correlation, prioritization, trends, and behavior baselines for monitoring and analysis.
  • Identify vulnerabilities and attack-surface weaknesses and apply mitigations.
  • Perform threat hunting using internal/external intelligence, TIPs, STIX/TAXII, Sigma, YARA, and Snort.
  • Perform incident response including malware analysis, reverse engineering, metadata analysis, data recovery, and root-cause analysis.

Before you certify

Requirements and recommended experience

Recommended experience

Minimum 10 years of general hands-on IT experience, including 5 years of hands-on security

Recommended

Network+, Security+, CySA+, Cloud+, and PenTest+ or equivalent knowledge

Corporate certification enablement

Turn this pathway into a team capability plan

We can align the learning path, instructor support, practice environment and delivery schedule to your team’s roles and certification target.