I just passed CompTIA SecurityX — formerly known as CASP+ — on my first attempt. This post is a rundown of how I studied for it, what actually helped, and what I'd tell someone else about to sit the exam.

CompTIA SecurityX (CAS-005) covers four domains:

  1. Governance, Risk, and Compliance (~20%)
  2. Security Architecture (~30%)
  3. Security Engineering (~30%)
  4. Security Operations (~20%)

Background

SecurityX sits above Security+ in CompTIA's cybersecurity track, aimed more at people doing hands-on engineering and architecture work rather than pure management or compliance. Given my day-to-day is infrastructure, DevOps, and security engineering it felt like the right fit — less "define the CIA triad" and more "here's a scenario, design the solution."

How I Studied

I didn't follow a single course. Instead I combined a few different resources, which ended up covering both the theory and the hands-on side:

  • The official CompTIA SecurityX study guide — for structure and to make sure I wasn't missing any domains.
  • AI sessions covering practice questions — going through exam-style questions and using them as a way to dig into why an answer was right or wrong, not just memorising the correct option.
  • TryHackMe rooms from the Security Engineer path — for the more architecture- and engineering-heavy material.
  • TryHackMe rooms from the SOC Level 1 path — to round out the detection and monitoring side, which overlaps more than you'd expect with the engineering-focused exam objectives.

The combination worked well because the official guide gave me the map, and the TryHackMe paths + practice questions gave me the actual muscle memory — enough repetition on real scenarios that the exam's case-study style questions didn't feel unfamiliar.

What Helped Most

If I had to rank it, the practice questions and the TryHackMe rooms did more for me than re-reading the guide cover to cover. SecurityX leans heavily on scenario-based questions — given this environment, what's the best control — and that's a skill you build by working through examples, not by memorising definitions.

Takeaway

One pass, no retakes. If you're already working hands-on in security or infrastructure, SecurityX rewards that experience more than it tests raw recall. Pairing an official guide for coverage with practical labs (TryHackMe) and active practice questions for pressure-testing your knowledge seems to be a solid formula.