SecurityX/CASP+: architecture and secure operations
Eight lessons, 50 questions, and eight cases on risk, architecture, cryptography, delivery, and security operations.
Objectives and progression
Initial course with eight lessons and 58 original decisions in fictional APS and IT-project contexts. Internal assessment of 32 decisions in 70 minutes. Initial coverage of all four domains; advanced enterprise integration, OT/IoT, hardware security, threat hunting, and labs need deeper study. SecurityX is the current name of former CASP+. CAS-005 / V5 since 2024-12-17, with objectives 3.0. Pass/fail without a numeric score. Retirement in 2027 is only estimated.
Audience: Architects, security engineers, APS/L3 professionals, and technical owners of critical services.
Prerequisites: Strong systems, networking, and security foundations. CompTIA recommends ten years of hands-on IT including five in security; prior certification is not required to study here.
460 estimated study minutes
- Turn findings into decisions with authority, criteria, and expiry.
- Assess data flows and require suitable acquisition evidence.
- Distinguish server recovery from service recovery.
- Design resource-specific authorization and explicit responsibilities.
- Separate identity, key purpose, and encrypted-data lifecycle.
- Bind configuration, artifacts, and evidence through production.
- Measure coverage and limits before interpreting absent alerts.
- Close incidents and projects with demonstrated operational capability.
Modules
- Governance, risk, and exceptions
- Suppliers, data, and threats
- Resilience and recovery dependencies
- Identity, zero trust, and cloud
- Certificates, keys, and cryptography
- Engineering and secure delivery
- Telemetry and detection quality
- Response, recovery, and handover
Continue learning
References and version
CAS-005 / SecurityX V5; objectives 3.0; launched 2024-12-17
- CompTIA SecurityX current exam facts · 2026-09-30
- SecurityX CAS-005 objectives · 2026-09-30
- Zero trust architecture · 2026-09-30
- Contingency planning, RTO and RPO · 2026-09-30
- Cybersecurity Framework 2.0 · 2026-09-30
- Secure Software Development Framework 1.1 · 2026-09-30
- SSDF publication status · 2026-09-30
- ML-KEM key establishment · 2026-09-30
- ML-DSA digital signatures · 2026-09-30
- KMS key material rotation · 2026-09-30
- KMS key deletion lifecycle · 2026-09-30
- AWS Backup Vault Lock · 2026-09-30
- Shared responsibility model · 2026-09-30
- Confused deputy prevention · 2026-09-30
- TLS service identity · 2026-09-30
- PKIX certificate and extension constraints · 2026-09-30
- TLS 1.3 replay and early data · 2026-09-30
- Terraform sensitive values and state · 2026-09-30
- Ansible check and diff modes · 2026-09-30
- Kubernetes Pod Security Standards · 2026-09-30
- Collector resiliency · 2026-09-30
- SLSA artifact and provenance verification · 2026-09-30
- Incident response within cybersecurity risk management · 2026-09-30
- Enterprise patch management planning · 2026-09-30
- Prompt injection risks and controls · 2026-09-30
What you will explore
0 / 8Governance, risk, and exceptions
Turn findings into decisions with authority, criteria, and expiry.
Suppliers, data, and threats
Assess data flows and require suitable acquisition evidence.
Resilience and recovery dependencies
Distinguish server recovery from service recovery.
Identity, zero trust, and cloud
Design resource-specific authorization and explicit responsibilities.
Certificates, keys, and cryptography
Separate identity, key purpose, and encrypted-data lifecycle.
Engineering and secure delivery
Bind configuration, artifacts, and evidence through production.
Telemetry and detection quality
Measure coverage and limits before interpreting absent alerts.
Response, recovery, and handover
Close incidents and projects with demonstrated operational capability.