CompTIA SecurityX CAS-005 Lessons
Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.
- Policies, standards, procedures and guidelines, and why the difference is examinableObjective 1.1
- An enterprise lab you cannot actually build, and what to build instead
- Running the programme: training, communication, reporting and RACIObjective 1.2
- COBIT, ITIL and the frameworks that govern IT rather than securityObjective 1.3
- Asset life cycle, the CMDB, and an inventory you can trustObjective 1.4
- GRC tooling: mapping a control once and tracking compliance automaticallyObjective 1.5
- Data governance across production, development, testing and QAObjective 1.6
- Risk assessment: quantitative, qualitative, and the third party you cannot auditObjective 1.7
- Threat modelling with STRIDE, ATT&CK and CAPECObjective 1.8
- Attack surface: architecture reviews, data flows and trust boundariesObjective 1.9
- PCI DSS, ISO/IEC 27000 and industry-specific obligationsObjective 1.10
- NIST, the CSF, CSA, and choosing a framework you can actually runObjective 1.11
- CASB, shadow IT detection, and the shared responsibility lineObjective 2.1
- Securing the pipeline: CI/CD, Terraform and AnsibleObjective 2.1
- Container, orchestration and serverless workload securityObjective 2.1
- Cloud data exposure, leakage and remanenceObjective 2.2
- Encryption keys in the cloud, and who actually holds themObjective 2.2
- Choosing proactive, detective and preventative controls in the cloudObjective 2.3
- Customer-to-cloud connectivity, service integration and continuous authorizationObjective 2.3
- Segmentation and microsegmentation, and the difference that mattersObjective 2.4
- VPN, always-on VPN, and integrating security through APIsObjective 2.4
- Asset identification, management and attestationObjective 2.5
- Data perimeters and secure zonesObjective 2.5
- Deperimeterization: SASE, SD-WAN and software-defined networkingObjective 2.6
- Zero trust: subjects, objects, and the decision in betweenObjective 2.7
- Scripting for security: PowerShell, Bash and PythonObjective 3.1
- Infrastructure as code, cloud APIs and event triggersObjective 3.1
- SOAR, playbooks and workflow automationObjective 3.1
- Generative AI in security work, and automated patchingObjective 3.1
- Vulnerability scanning: strategy before toolingObjective 3.2
- SCAP: OVAL, XCCDF, CPE and what the acronyms buy youObjective 3.2
- CVE, CVSS, and a report somebody acts onObjective 3.2
- Post-quantum cryptography and what to do about it nowObjective 3.3
- Homomorphic encryption, forward secrecy and data in useObjective 3.3
- Key stretching, hardware acceleration and where crypto actually runsObjective 3.3
- Cryptographic use cases: data at rest, in transit and in useObjective 3.4
- Secure email and certificate-based authenticationObjective 3.4
- Blockchain, privacy technologies and compliance use casesObjective 3.4
- Tokenisation, hashing and digital signaturesObjective 3.5
- Code signing and cryptographic eraseObjective 3.5
- SIEM: getting events in, parsing them, and keeping themObjective 4.1
- False positives, false negatives, and tuning without going blindObjective 4.1
- Correlation, prioritisation and behaviour baselinesObjective 4.1
- Injection, cross-site scripting and insecure configurationObjective 4.2
- Mitigations: input validation, patching, encryption and defence in depthObjective 4.2
- Threat hunting: internal and external intelligenceObjective 4.3
- Sharing what you find: STIX, TAXII, Sigma, YARA and SnortObjective 4.3
- Directing malware analysis and reverse engineeringObjective 4.4
- Metadata analysis, data recovery and root causeObjective 4.4