Home  /  Blog

Is CompTIA SecurityX (CAS-005) at the Level of CISSP?

Cybersecurity & Governance·4 min read·PractiseExam

If you are weighing CompTIA SecurityX (formerly CASP+, exam code SECURITYX) against the CISSP, you are really asking two questions: is it as hard, and is it worth the effort? The honest answer to the first is that they are different animals. CISSP is a broad management-oriented exam. SecurityX is a hands-on, practitioner-level exam aimed at the person who actually designs and runs security in an enterprise. Both are advanced. Neither is a certification you pass by cramming a week of flashcards.

This post walks through what the SecurityX exam actually looks like, where the difficulty comes from, and how to prepare without wasting time.

What the SecurityX exam looks like

The current CompTIA SecurityX exam gives you up to 90 questions and 165 minutes. That works out to a little under two minutes per question on average, roughly 110 seconds, which sounds comfortable until you meet the questions themselves. The delivery is linear, so you move forward through the paper rather than jumping around freely, and you should not expect to leave large stretches of time to circle back.

The reason the clock matters is the question style. SecurityX leans on scenario-heavy, multi-response items and interactive performance-based tasks. These are not recall questions. A single item can describe an architecture, a threat, and a set of constraints, then ask you to pick the combination of controls that actually fits. That is where the perceived difficulty lives, and it is why a good CompTIA SecurityX mock test is worth more than another read-through of a study guide.

The four domains and their weights

SecurityX is built around four domains. Security engineering carries the most weight, followed closely by security architecture, which tells you where CompTIA expects most working professionals to spend their day. Governance, risk, and compliance is present but is the smallest slice, another point of contrast with CISSP, where governance looms larger.

CompTIA SecurityX (SECURITYX) domain weightings, per the official CompTIA SecurityX exam page, verified 24 August 2026.
DomainWeight
Security engineering31%
Security architecture27%
Security operations22%
Governance, risk, and compliance20%

Use these weights to plan your study time honestly. If more than half the paper is engineering and architecture, that is where the bulk of your practice belongs. A SecurityX mock test pack lets you drill each domain at its real proportion rather than guessing.

Is it really at CISSP level?

In terms of raw difficulty, yes, SecurityX belongs in the same conversation. The gap is one of emphasis rather than rigour. CISSP asks you to think like a security manager balancing risk, policy, and budget. SecurityX asks you to think like a senior engineer who has to make the architecture actually secure. Someone strong on the technical side often finds SecurityX the more natural fit, and vice versa. If you have passed one, do not assume the other is a formality.

What our mock contains, plainly

Here is the honest disclosure. The real CompTIA SecurityX exam includes performance-based questions, interactive tasks rather than multiple choice. Our mock is multiple-choice and multiple-response only. It covers every domain at its official weighting and matches the 90-question, 165-minute format, but you will not practise the interactive interface here. Treat the mock as the way to harden your knowledge and pace; plan to rehearse the performance-based tasks separately through hands-on labs.

How do I pass SECURITYX?

So how do I pass SECURITYX without months of guesswork? Three things. First, respect the domain weights above and give engineering and architecture the time they demand. Second, practise under the real clock, because 110 seconds per multi-response scenario is where unprepared candidates lose. Third, get hands-on with the interactive tasks the mock cannot reproduce.

A realistic practise exam for advanced security work is the fastest way to find your weak domains before exam day finds them for you. Sit a full-length paper, review every wrong answer against the domain it came from, and repeat until your timing and your accuracy both hold up. When you are ready to train seriously, you can buy a SecurityX mock test pack and work through it domain by domain. SecurityX is hard, but it is a knowable kind of hard, and a good mock test turns most of the surprise into preparation.

CompTIASECURITYXSecurityXCASP