1. Home
  2. CompTIA
  3. CAS-005 Exam

CAS-005 CompTIA SecurityX Certification Exam Topics and Questions

Let's Practice Free CompTIA CAS-005 Questions Aligned with Official Exam Topics

Follows CompTIA's official outline Updated 02 Sep, 2026 4 Topics
Reviewed by Thomas Lee, CompTIA CAS-005 Certified Professional
Topic Content
Security Architecture encompasses the analysis of organizational requirements to design and implement resilient systems that can withstand threats and maintain operational continuity. This section focuses on strategic component placement within network infrastructure, ensuring optimal positioning of security controls and systems. Advanced security engineers will learn to configure and deploy firewalls effectively, establishing robust perimeter defenses and internal segmentation policies. The curriculum covers Intrusion Prevention Systems IPS deployment, tuning, and management to detect and block malicious activities in real-time. Participants will... See More
Sample Questions for Topic 1 : Security Architecture
Q1

Source code snippets for two separate malware samples are shown below:

Sample 1:

knockEmDown(String e) {

if(target.isAccessed()) {

target.toShell(e);

System.out.printIn(e.toString());

c2.sendTelemetry(target.hostname.toString + " is " + e.toString());

} else {

target.close();

}

}

Sample 2:

targetSys(address a) {

if(address.islpv4()) {

address.connect(1337);

address.keepAlive("paranoid");

String status = knockEmDown(address.current);

remote.sendC2(address.current + " is " + status);

} else {

throw Exception e;

}

}

Which of the following describes the most important observation about the two samples?

Topic Content
Governance, Risk, and Compliance encompasses the implementation of appropriate governance components aligned with organizational security requirements. Security architects must address critical threats including phishing attacks, social engineering tactics, and general security vulnerabilities while establishing robust communication and reporting mechanisms. This domain requires proficiency in frameworks such as COBIT, which provides structured guidance for IT governance and management practices. Organizations must develop comprehensive policies and procedures that define roles, responsibilities, and accountability measures across all security functions. The integration of governance... See More
Sample Questions for Topic 2 : Governance, Risk, and Compliance
Q2

A threat hunter is identifying potentially malicious activity associated with an APT. When the threat hunter runs queries against the SIEM platform with a date range of 60 to 90 days ago, the involved account seems to be typically most active in the evenings. When the threat hunter reruns the same query with a date range of 5 to 30 days ago, the account appears to be most active in the early morning. Which of the following techniques is the threat hunter using to better understand the data?

Topic Content
Security Engineering encompasses the practical application of security principles to design, implement, and maintain secure systems within enterprise environments. This domain focuses on troubleshooting and resolving common challenges related to identity and access management IAM components, which are critical for controlling who can access organizational resources and what actions they can perform. Professionals in this field must diagnose issues such as authentication failures, authorization problems, directory service misconfigurations, and access control policy violations that impact system security and user productivity.... See More
Topic Content
Security Operations encompasses the practical application of security monitoring, threat detection, and incident response capabilities. This domain evaluates a security architects ability to interpret security data, identify anomalies, and implement effective monitoring strategies across an organizations infrastructure. Professionals must demonstrate competency in analyzing logs, alerts, and network traffic to detect potential security incidents and threats in real-time. The focus extends to designing and deploying security information and event management SIEM systems, establishing baseline metrics, and creating response procedures that minimize... See More

Ready to Start Practicing?

Access all questions and start your exam preparation journey

Upgrade to Full CAS-005 Exam Questions 🚀
Exams Made Simple. Success Made Possible.