// COMPTIA CAS-005 · ADVANCED CYBERSECURITY PRACTITIONER SYSTEM ONLINE · COHORT 26-Q3 ENROLLING

PASS
THE SECURITYX
EXAM

The most rigorous training program for CompTIA SecurityX (CAS-005), the advanced certification for architects, senior engineers, and technical security leaders.

exam_id :: CAS-005
duration :: 165 min
questions :: 90 (max)
format :: Performance-based + multiple choice
prereq :: 10y IT · 5y security (recommended)
accreditation :: ANSI / ISO 17024
04domains
Governance, Architecture, Engineering, Operations
165min
Performance-based exam window
90questions
Maximum on the CAS-005 exam
5days
In-Person and Live Online cohort duration
// 01 — CERTIFICATION
About SecurityX

The terminal node of advanced cybersecurity practice.

SecurityX is the rename of CASP+, and the only hands-on, performance-based, ANSI-accredited cert at the master practitioner tier. This is not a beginner cert. It is built for engineers, architects, and operators who already run something in production.

The CompTIA SecurityX (CAS-005) certification validates the ability to architect, engineer, integrate, and implement secure solutions across complex environments (on-prem, cloud, and hybrid) while leading the governance and operational disciplines that keep a resilient enterprise resilient.

Where Security+ proves you understand the field, SecurityX proves you can operate the field. The exam emphasizes performance-based questions: cryptographic implementation, threat modeling, automation, incident response, and the application of emerging trends like AI in security operations.

Our bootcamp is engineered to mirror that depth. No surface-level review. No memorization grind. You will build, break, harden, and defend in real environments, and pass the exam as a side effect of becoming competent.

// EXAM SPECIFICATION v3.0 · 2024+
VendorCompTIA, Inc.
Exam CodeCAS-005
PredecessorCASP+ (deprecated)
QuestionsUp to 90
Duration165 minutes
FormatPBQ + MCQ
PassingPass / Fail (no scaled score)
Validity3 years (CEU renewable)
AccreditationANSI · ISO 17024 · DoD 8140
Recommended XP10y IT / 5y security
// 02 — DELIVERY FORMATS
// 03 — CURRICULUM
Exam Domains

Four domains. One integrated practice.

The CAS-005 blueprint maps to four interlocking domains. We don't teach them as silos, every lab forces you across at least two. Domain weights below reflect approximate exam distribution.

D / 01
Governance, Risk & Compliance
Risk management strategy, threat modeling, regulatory frameworks (GDPR, HIPAA, PCI-DSS, NIST), audit readiness, and the GRC tooling that ties them together.
~20%
D / 02
Security Architecture
Designing resilient enterprise architectures across on-prem, cloud, and hybrid. Zero-trust, segmentation, identity federation, cryptographic primitives, and emerging AI/ML-aware design.
~27%
D / 03
Security Engineering
Implementation work, IAM, endpoint hardening, PKI, secure software development integration, container and serverless security, and automation pipelines that ship secure-by-default.
~31%
D / 04
Security Operations
Detection engineering, threat hunting, incident response, forensics, and the automation layer that scales a SOC. Includes adversarial AI considerations and supply-chain incident scenarios.
~22%
// 04 — TARGET ROLES
Who it's for

Senior practitioners stepping into technical leadership.

SecurityX is the credential for engineers who already build secure systems and now need the formal recognition and framework to lead them. If any of these describe your next role, the bootcamp is built for you.

// ROLE 01

Security Architect

Designs the security posture of the whole enterprise. Translates business risk into technical control patterns across cloud, network, identity, and data layers.

DCWFSecurity Architect (652)
// ROLE 02

Senior Security Engineer

Hands-on builder. Implements detection pipelines, hardens infrastructure, integrates security tooling into DevOps, and owns the technical depth a SOC depends on.

DCWFISS Developer (631)
// ROLE 03

Application Security Architect

Owns the security model for products and platforms. Lives at the seam between engineering and security, threat models, SDL, secrets, and shift-left automation.

DCWFSecure Software Assessor (622)
// ROLE 04

SOC Manager / Lead

Runs detection and response. SecurityX validates the technical foundation under the management, the credential that says you can both lead and operate.

DCWFISS Manager (722)
// ROLE 05

Cloud Security Engineer

Designs and runs security controls native to AWS, Azure, and GCP. SecurityX's hybrid-architecture emphasis maps directly to the modern multi-cloud reality.

DCWFEnterprise Architect (651)
// ROLE 06

DoD / Federal Security

CompTIA SecurityX (CAS-005) is approved under DoDM 8140.03 for 19 DCWF work roles spanning IT, Cybersecurity, Software Engineering, and Cyberspace Enabler workforce elements. Often required for federal contractor positions.

DoD 814019 work roles
// MARKET BENCHMARKS · CYBERSECURITY ROLES
$124,910
U.S. median annual wage for information security analysts, May 2024. The highest 10 percent earned more than $186,420.
U.S. Bureau of Labor Statistics
$127,451
Reported average compensation for CASP+ certified professionals in the 2025 Skillsoft CompTIA certification salary data.
Skillsoft 2025 Salary Data
457,398
U.S. cybersecurity-related online job openings reported nationally for 2025. BLS projects 29 percent employment growth for information security analysts from 2024 to 2034.
CyberSeek · BLS

Salary varies by role, location, employer, clearance requirements, years of experience, education, prior certifications, and technical skill level. These figures are third-party market benchmarks and are not presented as guaranteed student outcomes.

// 05 — PROGRAM TIMELINE
Five-day intensive

A week that compounds.

The week is sequenced so each day's labs build on the previous. Mornings are conceptual deep dives; afternoons are hands-on environments. Day five ends with full exam simulations and a personalized study plan.

DAY 01

Governance & Risk

Regulatory landscape, threat modeling, risk quantification, GRC tooling, and policy frameworks that survive audit.

DAY 02

Architecture

Zero-trust patterns, segmentation, identity federation, cloud-native control mapping, cryptographic primitives in practice.

DAY 03

Engineering

IAM at scale, endpoint hardening, PKI, container/serverless security, secure SDLC integration, automation pipelines.

DAY 04

Operations

Detection engineering, threat hunting workflows, incident response, forensics fundamentals, SOAR automation.

DAY 05

Exam Simulation

Full-length performance-based simulations, gap analysis, study plan calibration, voucher scheduling and post-cohort support.

// 06 — FAQ
Common questions

Before you enroll.

Most candidates ask the same six questions. If yours isn't here, the team responds inside one business day.

Is SecurityX the same as CASP+?

Yes. CompTIA rebranded CASP+ as SecurityX with the CAS-005 exam release. Existing CASP+ credentials remain valid; the curriculum and audience are unchanged in spirit but updated for cloud, AI, and modern operations.

Do I really need 10 years of IT experience?

It's a recommendation, not a hard prerequisite. We screen every applicant; if you have strong fundamentals (Security+, CySA+, or equivalent hands-on work) we'll tell you honestly whether you're ready or whether to wait one cohort.

Is the exam voucher included?

Yes, every format includes one CAS-005 voucher and one retake voucher, plus 90 days of post-bootcamp lab access and instructor office hours.

Will this satisfy DoD 8140?

CompTIA SecurityX (CAS-005) is approved under DoDM 8140.03 for 19 DCWF work roles, including Security Architect (652), Information Systems Security Manager (722), Enterprise Architect (651), Information Systems Security Developer (631), Cyber Defense Analyst (511), Security Control Assessor (612), and others. DoDM 8140.03 replaced the legacy DoDM 8570.01-M framework (with its IAT, IAM, and IASAE categories) in February 2023; SecurityX inherits all approvals previously held by CASP+ under that framework. Verify the specific work role your contract requires against the current DoD 8140 Foundational Qualification Matrix at public.cyber.mil.

What's the difference between Live Online and Self-Paced?

Live Online is a real-time five-day cohort, same instructor, same schedule, virtual. Self-Paced is async with 90 days of lab access and twice-weekly group office hours. Pick Live Online if structure helps you finish; pick Self-Paced if your schedule won't tolerate five fixed days.

Can our company run this as a private cohort?

Yes. That is the Private Events format. Send us your stack and team size and we'll customize the labs to your environment, then deliver either at your facility or as a private online cohort. Cohorts of eight or more get a tailored scope review.

// 07 — LIBRARY
// 08 — ENROLL
Cohort 26-Q3 enrolling

Stop reading about it. Start running it.

The next live cohort opens July 14. Self-paced enrollment is rolling. Private event scopes are booked six to twelve weeks ahead. Tell us your format and we will send your enrollment packet inside one business day.

securityx@bootcamp:~
$ ./enroll --format live-online
→ Verifying cohort availability...
✓ Cohort 26-Q3 · 14 of 20 seats open
$ ./enroll --voucher include
✓ Exam voucher + retake included
$ ./enroll --labs 90d
✓ 90-day lab access provisioned
$ ./enroll --commit
→ Awaiting confirmation
ready_