CompTIA SecurityX CAS-005 Lessons

Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.

Practise with the exam simulator

  1. Policies, standards, procedures and guidelines, and why the difference is examinableObjective 1.1
  2. An enterprise lab you cannot actually build, and what to build instead
  3. Running the programme: training, communication, reporting and RACIObjective 1.2
  4. COBIT, ITIL and the frameworks that govern IT rather than securityObjective 1.3
  5. Asset life cycle, the CMDB, and an inventory you can trustObjective 1.4
  6. GRC tooling: mapping a control once and tracking compliance automaticallyObjective 1.5
  7. Data governance across production, development, testing and QAObjective 1.6
  8. Risk assessment: quantitative, qualitative, and the third party you cannot auditObjective 1.7
  9. Threat modelling with STRIDE, ATT&CK and CAPECObjective 1.8
  10. Attack surface: architecture reviews, data flows and trust boundariesObjective 1.9
  11. PCI DSS, ISO/IEC 27000 and industry-specific obligationsObjective 1.10
  12. NIST, the CSF, CSA, and choosing a framework you can actually runObjective 1.11
  13. CASB, shadow IT detection, and the shared responsibility lineObjective 2.1
  14. Securing the pipeline: CI/CD, Terraform and AnsibleObjective 2.1
  15. Container, orchestration and serverless workload securityObjective 2.1
  16. Cloud data exposure, leakage and remanenceObjective 2.2
  17. Encryption keys in the cloud, and who actually holds themObjective 2.2
  18. Choosing proactive, detective and preventative controls in the cloudObjective 2.3
  19. Customer-to-cloud connectivity, service integration and continuous authorizationObjective 2.3
  20. Segmentation and microsegmentation, and the difference that mattersObjective 2.4
  21. VPN, always-on VPN, and integrating security through APIsObjective 2.4
  22. Asset identification, management and attestationObjective 2.5
  23. Data perimeters and secure zonesObjective 2.5
  24. Deperimeterization: SASE, SD-WAN and software-defined networkingObjective 2.6
  25. Zero trust: subjects, objects, and the decision in betweenObjective 2.7
  26. Scripting for security: PowerShell, Bash and PythonObjective 3.1
  27. Infrastructure as code, cloud APIs and event triggersObjective 3.1
  28. SOAR, playbooks and workflow automationObjective 3.1
  29. Generative AI in security work, and automated patchingObjective 3.1
  30. Vulnerability scanning: strategy before toolingObjective 3.2
  31. SCAP: OVAL, XCCDF, CPE and what the acronyms buy youObjective 3.2
  32. CVE, CVSS, and a report somebody acts onObjective 3.2
  33. Post-quantum cryptography and what to do about it nowObjective 3.3
  34. Homomorphic encryption, forward secrecy and data in useObjective 3.3
  35. Key stretching, hardware acceleration and where crypto actually runsObjective 3.3
  36. Cryptographic use cases: data at rest, in transit and in useObjective 3.4
  37. Secure email and certificate-based authenticationObjective 3.4
  38. Blockchain, privacy technologies and compliance use casesObjective 3.4
  39. Tokenisation, hashing and digital signaturesObjective 3.5
  40. Code signing and cryptographic eraseObjective 3.5
  41. SIEM: getting events in, parsing them, and keeping themObjective 4.1
  42. False positives, false negatives, and tuning without going blindObjective 4.1
  43. Correlation, prioritisation and behaviour baselinesObjective 4.1
  44. Injection, cross-site scripting and insecure configurationObjective 4.2
  45. Mitigations: input validation, patching, encryption and defence in depthObjective 4.2
  46. Threat hunting: internal and external intelligenceObjective 4.3
  47. Sharing what you find: STIX, TAXII, Sigma, YARA and SnortObjective 4.3
  48. Directing malware analysis and reverse engineeringObjective 4.4
  49. Metadata analysis, data recovery and root causeObjective 4.4