Domain Weighting
Percentage of exam questions allocated to a specific content area.
Getting Started: How the Exam Works
Free knowledge base
Everything from the course in one searchable place: 240 entries. Use it to review before a practice test or look up a word you forgot.
240 results
Percentage of exam questions allocated to a specific content area.
Getting Started: How the Exam Works
Standard exam questions with one or more correct options.
Getting Started: How the Exam Works
Interactive simulations requiring hands-on problem-solving skills.
Getting Started: How the Exam Works
Minimum score required to successfully pass the certification exam.
Getting Started: How the Exam Works
Total time allotted to complete the certification examination.
Getting Started: How the Exam Works
The current exam code for the CompTIA SecurityX certification.
Getting Started: How the Exam Works
A raw score converted to a standardized scale, not used for CAS-005.
Getting Started: How the Exam Works
To remember the exam details: '90 questions in 165 minutes, score 750 to win it!'
Getting Started: How the Exam Works
The CAS-005 exam has a maximum of 90 questions and a duration of 165 minutes. The passing score is 750 on a scale of 100-900. Memorize these exact numbers.
Getting Started: How the Exam Works
Ignoring domain weightings and spending too much time on low-weighted topics.
Getting Started: How the Exam Works
Getting stuck on a single Performance-Based Question (PBQ) and running out of time for others.
Getting Started: How the Exam Works
Not practicing time management, leading to unanswered questions at the end of the exam.
Getting Started: How the Exam Works
CompTIA's official list of topics covered on the exam.
Getting Started: How the Exam Works
Engaging with material through discussion, practice, or teaching.
Getting Started: How the Exam Works
Reviewing information at increasing intervals to improve retention.
Getting Started: How the Exam Works
Systematic process to identify and mitigate potential threats.
Getting Started: How the Exam Works
Simulated exams to assess knowledge and identify weak areas.
Getting Started: How the Exam Works
NIST Special Publication on Computer Security Incident Handling Guide.
Getting Started: How the Exam Works
Threat modeling methodology: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege.
Getting Started: How the Exam Works
To remember key study steps: 'OATS' – Objectives, Active Learning, Time Management, Self-Assessment.
Getting Started: How the Exam Works
The CAS-005 exam expects you to not just recall definitions, but to apply concepts to complex scenarios. Look for keywords like 'recommend,' 'evaluate,' 'design,' or 'implement' in questions, as these indicate application-level thinking is required.
Getting Started: How the Exam Works
Relying solely on memorization without understanding the underlying concepts.
Getting Started: How the Exam Works
Neglecting practice tests until the last minute, missing opportunities to identify weaknesses.
Getting Started: How the Exam Works
Underestimating the importance of hands-on experience and practical application.
Getting Started: How the Exam Works
Ensuring IT aligns with business goals, manages risk, and delivers value.
Governance, Risk and Compliance
Framework for governing and managing enterprise IT, focusing on objectives.
Governance, Risk and Compliance
Framework for IT service management, focusing on best practices.
Governance, Risk and Compliance
High-level statement of management's intent and direction.
Governance, Risk and Compliance
Mandatory requirements for specific technologies or processes.
Governance, Risk and Compliance
Detailed, step-by-step instructions for performing a task.
Governance, Risk and Compliance
Minimum security configurations for systems or applications.
Governance, Risk and Compliance
Recommended actions or best practices, not mandatory.
Governance, Risk and Compliance
P-S-B-G-P: Policies Set Baselines, Guidelines Provide Procedures. (Think of it as a clear path from high-level rules to detailed steps!)
Governance, Risk and Compliance
The CAS-005 exam often tests your ability to distinguish between policies, standards, guidelines, and procedures. Remember their hierarchical relationship and mandatory nature.
Governance, Risk and Compliance
Confusing COBIT (governance 'what') with ITIL (service management 'how').
Governance, Risk and Compliance
Treating guidelines as mandatory requirements instead of recommendations.
Governance, Risk and Compliance
Failing to involve all stakeholders (e.g., legal, HR) when developing or updating policies.
Governance, Risk and Compliance
Holistic approach to managing all risks across an organization.
Governance, Risk and Compliance
Subjective assessment of risk likelihood and impact using descriptive scales.
Governance, Risk and Compliance
Objective, numerical assessment of risk using data and statistical methods.
Governance, Risk and Compliance
Eliminating a risk by discontinuing the activity that causes it.
Governance, Risk and Compliance
Reducing the likelihood or impact of a risk through controls.
Governance, Risk and Compliance
Shifting the financial burden of a risk to a third party, e.g., insurance.
Governance, Risk and Compliance
Consciously deciding to take no action against an identified risk.
Governance, Risk and Compliance
Metrics used to monitor and track the level of risk exposure.
Governance, Risk and Compliance
To remember the four risk treatment strategies, think of 'AMAT': Avoid, Mitigate, Accept, Transfer.
Governance, Risk and Compliance
The CAS-005 exam expects you to understand the ERM process as a continuous cycle and to distinguish clearly between the four risk treatment strategies. Pay close attention to the nuances of qualitative vs. quantitative analysis.
Governance, Risk and Compliance
Confusing risk mitigation with risk avoidance; mitigation reduces impact/likelihood, avoidance eliminates the risk entirely.
Governance, Risk and Compliance
Failing to understand that ERM is a continuous process, not a one-time assessment.
Governance, Risk and Compliance
Not documenting risk acceptance decisions; all risk treatment decisions, especially acceptance, must be formally recorded.
Governance, Risk and Compliance
EU law for data protection and privacy for all individuals within the EU.
Governance, Risk and Compliance
US law protecting sensitive patient health information from disclosure.
Governance, Risk and Compliance
California law granting consumers rights over their personal data.
Governance, Risk and Compliance
Data is subject to the laws of the country where it is stored.
Governance, Risk and Compliance
The official power to make legal decisions and judgments.
Governance, Risk and Compliance
A structured set of guidelines for meeting security standards.
Governance, Risk and Compliance
An official inspection of an organization's accounts or systems.
Governance, Risk and Compliance
To remember key data privacy laws: 'G-H-C-P-L' for GDPR, HIPAA, CCPA, PIPEDA, LGPD. Imagine a 'Grand Hippo Chasing Purple Lizards' across the globe!
Governance, Risk and Compliance
Memorize the core principles of GDPR (e.g., lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, accountability) as they are frequently referenced in exam questions about global data privacy.
Governance, Risk and Compliance
Assuming compliance with one regulation automatically covers others; many regulations have unique requirements.
Governance, Risk and Compliance
Neglecting to update compliance posture as laws and regulations evolve or as the business expands into new jurisdictions.
Governance, Risk and Compliance
Viewing compliance as a one-time project rather than an ongoing process requiring continuous monitoring and auditing.
Governance, Risk and Compliance
Framework of policies ensuring responsible, ethical, and legal AI development and use.
Governance, Risk and Compliance
Malicious input designed to trick or compromise an AI model.
Governance, Risk and Compliance
Injecting malicious data into an AI model's training set.
Governance, Risk and Compliance
Attack to reconstruct sensitive training data from an AI model's output.
Governance, Risk and Compliance
Crafting inputs that cause an AI model to misclassify or fail.
Governance, Risk and Compliance
To remember STRIDE: 'STRong IDentity Ensures Data security.' (Spoofing, Tampering, Repudiation, Info Disclosure, DoS, EoP)
Governance, Risk and Compliance
For the CAS-005 exam, understand the core purpose of threat modeling and be able to identify the components of common methodologies like STRIDE and DREAD. Also, recognize the unique security and ethical challenges of AI systems and the role of governance.
Governance, Risk and Compliance
Treating threat modeling as a one-time event, rather than an iterative process throughout the system lifecycle.
Governance, Risk and Compliance
Focusing only on technical vulnerabilities and neglecting business logic or human element threats.
Governance, Risk and Compliance
Ignoring the unique security challenges of AI systems, assuming traditional cybersecurity is sufficient.
Governance, Risk and Compliance
Ability of a system to recover from failures and continue functioning.
Security Architecture
System's ability to operate despite the failure of one or more components.
Security Architecture
Maximizing system uptime and minimizing service interruptions.
Security Architecture
Ability of a system to handle increased workload or demand.
Security Architecture
Duplication of critical components to prevent single points of failure.
Security Architecture
Speed and ease with which a system can be restored after a disruption.
Security Architecture
Using different technologies or vendors to avoid common mode failures.
Security Architecture
Remember 'FRAS': Fault tolerance, Recoverability, Availability, Scalability – the pillars of resilience.
Security Architecture
The CAS-005 exam frequently tests your understanding of the differences and overlaps between security, resilience, and availability. Look for keywords like 'maintain service during disruption' or 'recover quickly' to identify resilience-focused questions.
Security Architecture
Confusing resilience solely with security; they are distinct but complementary.
Security Architecture
Designing for resilience only after a system is built, instead of from the ground up.
Security Architecture
Failing to regularly test resilience mechanisms, leading to false confidence.
Security Architecture
Reusable, proven solution to common security problems in system architecture.
Security Architecture
Granting minimum necessary permissions to a user or system component.
Security Architecture
Layering multiple security controls to protect resources.
Security Architecture
System failure defaults to denial of access or unauthorized operations.
Security Architecture
Requiring multiple individuals to complete a critical task.
Security Architecture
Combining security technologies into a cohesive, centrally managed system.
Security Architecture
Embedding security early in the SDLC to identify vulnerabilities sooner.
Security Architecture
To remember key secure design patterns: 'L.D.F.S.S.' - Least Privilege, Defense in Depth, Fail Secure, Separation of Duties, Secure Defaults.
Security Architecture
The CAS-005 exam expects you to differentiate between various secure design patterns and understand their application in real-world scenarios. Pay close attention to the benefits of integrated security solutions and how security is woven into every stage of the SDLC, not just at the end.
Security Architecture
Treating security as an afterthought, only addressing it at the end of development.
Security Architecture
Granting overly broad permissions instead of adhering to the Principle of Least Privilege.
Security Architecture
Implementing disparate security tools that don't communicate or share intelligence.
Security Architecture
Security model: never trust, always verify every access request.
Security Architecture
System that grants, denies, or revokes access to resources.
Security Architecture
System that evaluates policies to make access decisions.
Security Architecture
Dividing networks into small, isolated segments for granular control.
Security Architecture
Security state and compliance of an endpoint device.
Security Architecture
Automatic trust based on network location (traditional security).
Security Architecture
V.E.R.I.F.Y.: Verify explicitly, Enforce least privilege, Rely on context, Isolate segments, Focus on data, Yield to continuous monitoring.
Security Architecture
The CAS-005 exam heavily emphasizes the core principles and components of Zero Trust. Be prepared to differentiate Zero Trust from traditional perimeter security and identify key implementation steps. Keywords like 'never trust, always verify,' 'microsegmentation,' 'least privilege,' and 'continuous verification' are critical.
Security Architecture
Believing Zero Trust is a product you can buy, rather than an architectural approach and philosophy.
Security Architecture
Attempting to implement Zero Trust all at once instead of through a phased, iterative process.
Security Architecture
Neglecting the importance of identity and device posture in a Zero Trust model, focusing only on network segmentation.
Security Architecture
Defines security duties between CSP and customer.
Security Architecture
Tools to identify cloud misconfigurations and compliance issues.
Security Architecture
Enforces security policies between cloud users and providers.
Security Architecture
Combines on-premise with public/private cloud services.
Security Architecture
Cloud model offering virtualized computing resources.
Security Architecture
Cloud model offering platform for developing, running, managing apps.
Security Architecture
Cloud model offering ready-to-use applications over the internet.
Security Architecture
C-S-P: 'Cloud Secures Platform' (CSP) for the Provider, 'Customer Secures Payload' (CSP) for the Customer. Helps remember the split!
Security Architecture
The CAS-005 exam heavily emphasizes the shared responsibility model. Memorize the division of responsibilities for IaaS, PaaS, and SaaS, as questions often test your understanding of who is accountable for specific security controls in each model.
Security Architecture
Assuming the cloud provider handles all security; remember the shared responsibility model.
Security Architecture
Neglecting to apply least privilege principles to cloud IAM roles and policies.
Security Architecture
Failing to encrypt data both at rest and in transit within cloud and hybrid environments.
Security Architecture
Data stored on physical or digital media.
Security Architecture
Data moving across a network or between systems.
Security Architecture
Data actively being processed by a computer system.
Security Architecture
Data Loss Prevention; systems to prevent unauthorized data transfer.
Security Architecture
Replacing sensitive data with realistic, fictitious data.
Security Architecture
Replacing sensitive data with a non-sensitive surrogate (token).
Security Architecture
Rules for how long data must be kept.
Security Architecture
Destroying encryption keys to render data unreadable.
Security Architecture
Remember 'RAT' for Data States: Rest, At, Transit. Protection for RATs: Encryption, Access Control, TLS.
Security Architecture
The CAS-005 exam expects you to know the three states of data (at rest, in transit, in use) and the primary protection methods for each. Also, be able to distinguish between data masking and tokenization, and understand the purpose of DLP.
Security Architecture
Confusing data masking with encryption; masking changes the data for non-production use, while encryption protects it in all states.
Security Architecture
Assuming DLP is a 'set it and forget it' solution; it requires continuous tuning and policy updates to be effective.
Security Architecture
Neglecting data destruction. Simply deleting files does not securely remove data; proper methods are crucial.
Security Architecture
Verifying a user's identity.
Security Engineering
Determining what an authenticated user can do.
Security Engineering
Tracking user activities and resource access.
Security Engineering
Requiring two or more distinct types of credentials.
Security Engineering
Permissions assigned to roles, not individuals.
Security Engineering
Using a single identity across multiple security domains.
Security Engineering
One authentication event for multiple applications.
Security Engineering
AAA: Always Authenticate, Always Authorize, Always Account. Remember these three pillars for IAM.
Security Engineering
For CAS-005, understand the distinctions and use cases for DAC, MAC, RBAC, and ABAC. Be prepared to identify appropriate access control models for various scenarios. Also, know the primary protocols for federation: SAML and OpenID Connect.
Security Engineering
Confusing authentication with authorization: Authentication proves who you are; authorization determines what you can do.
Security Engineering
Neglecting deprovisioning processes: Failing to promptly remove access for terminated employees creates orphaned accounts and serious security risks.
Security Engineering
Over-privileging users: Granting more access than necessary (violating least privilege) significantly increases the attack surface if an account is compromised.
Security Engineering
Process of securing a system by reducing its attack surface and vulnerabilities.
Security Engineering
The sum of all points where an unauthorized user can try to enter or extract data from a system.
Security Engineering
A set of minimum security configurations and best practices for a system.
Security Engineering
The process of acquiring, testing, and applying code changes to fix vulnerabilities.
Security Engineering
Automated process to identify security weaknesses in systems, networks, or applications.
Security Engineering
A software firewall running on an individual endpoint or server to control network traffic.
Security Engineering
When a system's configuration deviates from its intended or baseline security state.
Security Engineering
To 'Harden' a system, remember: R.A.P.I.D. — Remove unnecessary, Apply patches, Protect physically, Implement least privilege, Disable defaults.
Security Engineering
The CAS-005 exam expects you to differentiate between various hardening techniques for different system types (OS, applications, network, physical) and understand their practical implementation, often referencing industry standards like CIS Benchmarks.
Security Engineering
Forgetting that hardening is an ongoing process, not a one-time task; new vulnerabilities emerge daily.
Security Engineering
Over-hardening a system to the point where it impacts functionality or user productivity, leading to workarounds.
Security Engineering
Relying solely on default vendor security settings without further customization or review.
Security Engineering
Systems controlling industrial processes, prioritizing safety and availability.
Security Engineering
Hardware/software monitoring and controlling physical processes, e.g., manufacturing.
Security Engineering
Network of physical objects with sensors, software, connecting to the internet.
Security Engineering
Large-scale ICS for monitoring and controlling geographically dispersed facilities.
Security Engineering
Industrial computer control system automating specific processes.
Security Engineering
Reference model for segmenting ICS/OT networks into logical layers.
Security Engineering
IoT applied to industrial settings, often merging with OT.
Security Engineering
Physical isolation of a network from other networks, especially the internet.
Security Engineering
To secure OT, remember 'S.A.F.E.T.Y.': Segmentation, Authentication, Firmware, Encryption, Training, Yet-to-come (future threats).
Security Engineering
The CAS-005 exam expects you to differentiate between IT, OT, and IoT security priorities (confidentiality vs. availability/safety). Know the Purdue Model's layers and their purpose in OT segmentation. Be aware of common OT-specific malware (Stuxnet, Industroyer, Triton) and IoT botnets (Mirai).
Security Engineering
Treating OT/IoT security with the same approach as traditional IT security, ignoring their unique priorities (e.g., availability over confidentiality for OT).
Security Engineering
Failing to implement proper network segmentation between IT and OT environments, creating a direct path for attacks.
Security Engineering
Neglecting to inventory and manage IoT devices, leading to 'shadow IoT' and unpatched vulnerabilities.
Security Engineering
Performing tasks with minimal human intervention.
Security Engineering
Coordinating multiple automated tasks across systems.
Security Engineering
Security Orchestration, Automation, and Response platform.
Security Engineering
Step-by-step guide for incident response actions.
Security Engineering
Detailed instructions for routine operational tasks.
Security Engineering
Contextualized knowledge about existing or emerging threats.
Security Engineering
Organized approach to managing and recovering from security breaches.
Security Engineering
SOAR: S-O-A-R, Security Operations Are Rapid with SOAR!
Security Engineering
The CAS-005 exam expects you to differentiate clearly between automation (single task) and orchestration (coordinated workflows). Also, know what SOAR stands for and its primary function in integrating tools and playbooks.
Security Engineering
Confusing automation with orchestration: Automation is a single task; orchestration is coordinating many tasks.
Security Engineering
Believing SOAR replaces human analysts: SOAR augments analysts, handling repetitive tasks so humans can focus on complex problems.
Security Engineering
Implementing automation without clear processes: Automation without well-defined playbooks or runbooks can lead to errors or unexpected outcomes.
Security Engineering
Algorithms secure against quantum and classical computers.
Security Engineering
Quantum algorithm breaking RSA and ECC encryption.
Security Engineering
PQC type based on hard problems in high-dimensional lattices.
Security Engineering
NIST-selected PQC for key encapsulation mechanisms.
Security Engineering
NIST-selected PQC for digital signature algorithms.
Security Engineering
Physical device for secure cryptographic key storage and ops.
Security Engineering
Centralized system for managing crypto keys lifecycle.
Security Engineering
Regularly replacing old keys with new ones.
Security Engineering
Quantum computers are 'SHOR'ing' up trouble, so we need 'LATTICE' work with 'CRYSTALS' to keep our keys 'MANAGED'.
Security Engineering
The CAS-005 exam expects you to understand the *why* behind PQC – the quantum threat to current crypto. Memorize the names of the NIST-selected PQC algorithms (e.g., CRYSTALS-Kyber, CRYSTALS-Dilithium) and the core phases of the key management lifecycle.
Security Engineering
Assuming current encryption will always be sufficient; quantum threats are real and require proactive planning.
Security Engineering
Neglecting the full key lifecycle; key generation is just one part, secure storage and destruction are equally vital.
Security Engineering
Underestimating the complexity of PQC migration; it's a multi-year effort, not a quick fix.
Security Engineering
System aggregating and analyzing security logs for threat detection.
Security Operations
Endpoint Detection and Response; monitors and responds to threats on devices.
Security Operations
Mean Time To Detect; average time from incident start to detection.
Security Operations
Mean Time To Respond; average time from detection to full resolution.
Security Operations
User and Entity Behavior Analytics; detects anomalies in user/system behavior.
Security Operations
A documented set of procedures for handling security incidents.
Security Operations
An alert indicating a threat when no actual threat exists.
Security Operations
To remember the NIST IR phases: 'P.D.C.E.R.P.' – 'Prepared Detectives Contain Every Rogue Perpetrator.'
Security Operations
The CAS-005 exam expects you to know the phases of the NIST incident response lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity) and differentiate between various security monitoring tools like SIEM, EDR, and UEBA.
Security Operations
Confusing IDS (detection only) with IPS (detection and prevention).
Security Operations
Skipping the 'lessons learned' phase of incident response, leading to repeated incidents.
Security Operations
Over-relying on automated tools without human oversight and tuning, resulting in alert fatigue or missed threats.
Security Operations
A weakness in a system that can be exploited by a threat actor.
Security Operations
Simulated cyberattack to find exploitable vulnerabilities.
Security Operations
A piece of software or data that takes advantage of a vulnerability.
Security Operations
Gathering information about a target before an attack or test.
Security Operations
Extracting information about resources from a target system.
Security Operations
Common Vulnerabilities and Exposures, a list of publicly disclosed security flaws.
Security Operations
SCAN finds the 'S-pots,' PENTEST 'P-roves' the breach.
Security Operations
The CAS-005 exam expects you to differentiate between the goals, methodologies, and outcomes of vulnerability scanning versus penetration testing. Pay close attention to the 'active exploitation' aspect of pentesting.
Security Operations
Confusing vulnerability scanning with penetration testing; scanning identifies, pentesting exploits.
Security Operations
Failing to define the scope and rules of engagement before conducting a penetration test.
Security Operations
Not regularly updating vulnerability scanners or their vulnerability databases.
Security Operations
Proactive, human-driven search for hidden threats.
Security Operations
Duration an attacker remains undetected in a system.
Security Operations
Hunting based on a theory about attacker activity.
Security Operations
Hunting by detecting deviations from normal behavior.
Security Operations
Tactics, Techniques, and Procedures of adversaries.
Security Operations
Indicators of Compromise; evidence of a breach.
Security Operations
Hunters Collect And Discover Actions to Enrich security. (Hypothesis, Collect, Analyze, Discover, Action, Enrich)
Security Operations
The CAS-005 exam emphasizes proactive security measures. Be prepared to distinguish threat hunting from incident response and vulnerability management. Keywords like 'proactive search,' 'human-driven,' 'unknown threats,' and 'reducing dwell time' are strong indicators for threat hunting questions.
Security Operations
Confusing threat hunting with incident response; hunting is proactive, IR is reactive.
Security Operations
Relying solely on automated alerts instead of actively searching for unknown threats.
Security Operations
Not having sufficient data logging or retention to support effective hunting efforts.
Security Operations
Understanding a security event, its impact, and recovery.
Security Operations
Scientific process of collecting and analyzing digital evidence.
Security Operations
Documented chronological record of evidence handling.
Security Operations
Creating a bit-for-bit copy of a storage medium.
Security Operations
Analysis of RAM to find ephemeral evidence.
Security Operations
Recovering deleted or fragmented data from storage.
Security Operations
Creating a unique digital fingerprint for data integrity.
Security Operations
PICAP: Prepare, Identify, Collect, Analyze, Present. Remember it like a 'PICAP' (pickup) truck carrying evidence!
Security Operations
The CAS-005 exam emphasizes the forensic process steps and the importance of chain of custody. Memorize the order of the forensic phases and understand why each step is critical for evidence admissibility. Look for keywords like 'integrity', 'admissibility', and 'documentation'.
Security Operations
Failing to maintain a strict chain of custody, which can invalidate evidence.
Security Operations
Modifying original evidence during collection, leading to loss of integrity.
Security Operations
Not documenting every step of the forensic process thoroughly.
Security Operations