
CompTIA SecurityX
CompTIA SecurityX training prepares experienced cybersecurity professionals for the CAS-005 certification by covering enterprise security architecture, engineering, operations, governance, risk, and compliance. Participants study secure design for cloud, on-premises, and hybrid environments, including zero trust, cryptography, identity controls, automation, threat management, incident response, and vulnerability management.
No sessions available
Check back later or contact a provider directly.
Description
CompTIA SecurityX training prepares experienced cybersecurity professionals for the CAS-005 certification by covering enterprise security architecture, engineering, operations, governance, risk, and compliance.
Participants study secure design for cloud, on-premises, and hybrid environments, including zero trust, cryptography, identity controls, automation, threat management, incident response, and vulnerability management. Delivery may include instructor-led lessons, scenario discussions, practice questions, and hands-on labs aligned to exam objectives.
After completion, learners can assess complex security requirements, design controls, support security operations, and prepare for the CompTIA SecurityX exam.
What You Will Learn
Module 1: Governance, Risk, and Compliance
Security program documentation, including policies, standards, procedures, guidelines, and reporting structures.
Risk management practices for enterprise environments, including third-party risk, supply chain risk, business continuity, and disaster recovery.
Governance and compliance frameworks such as COBIT, ITIL, NIST CSF, ISO/IEC 27000, PCI DSS, SOC 2, and privacy regulations.
Module 2: Security Architecture
Secure architecture for on-premises, cloud, and hybrid environments.
Zero trust concepts, network segmentation, secure data flows, trust boundaries, and control placement.
Threat modeling methods such as MITRE ATT&CK, Cyber Kill Chain, STRIDE, OWASP, and attack surface analysis.
Module 3: Security Engineering
Identity and access management, cryptography, PKI, data protection, endpoint controls, and secure system integration.
Cloud security controls, automation, configuration management, and secure deployment practices.
AI-related security risks, including prompt injection, data exposure, model abuse, and governance controls.
Module 4: Security Operations
Threat detection, vulnerability management, incident response, security monitoring, and log analysis.
Use of SIEM, SOAR, DLP, endpoint detection, and response processes in enterprise operations.
Scenario-based exercises and performance-style practice tasks that reflect CompTIA SecurityX exam objectives.
Training commonly combines instructor-led lessons, case studies, hands-on labs, and exam-focused review. After completion, participants should be able to assess complex security requirements, design suitable controls, support secure implementation, and prepare for the CompTIA SecurityX certification exam.
Certification & Exam
Participants who complete this course can prepare for the CompTIA SecurityX certification, exam CAS-005. The certification is earned by passing the CompTIA exam, not by course attendance alone.
CAS-005 includes up to 90 multiple-choice and performance-based questions, with a 165-minute test time and pass/fail scoring. It covers governance, risk, and compliance, security architecture, security engineering, and security operations.
CompTIA recommends at least 10 years of hands-on IT experience, including 5 years in hands-on IT security.
After passing, candidates receive the CompTIA SecurityX credential, which is aimed at senior security engineer and security architect responsibilities. Reference: official CompTIA SecurityX certification page.
What You Will Achieve
After completing training aligned to the CompTIA SecurityX CAS-005 exam objectives, participants should be able to:
Apply governance, compliance, risk management, and threat-modeling strategies across enterprise security programs.
Implement security governance components, including policies, procedures, standards, guidelines, RACI matrices, change management, CMDB practices, and GRC tools.
Analyze organizational risk using quantitative and qualitative methods, including third-party risk, supply chain risk, business continuity, disaster recovery, data sovereignty, and breach response considerations.
Create threat models using MITRE ATT&CK, CAPEC, Cyber Kill Chain, Diamond Model, STRIDE, and OWASP methods to identify attack surfaces, trust boundaries, data flows, and likely attack paths.
Design resilient security architectures for cloud, on-premises, and hybrid environments using controls such as firewalls, IDS, IPS, VPN, NAC, WAF, proxies, API gateways, CDN services, centralized logging, and continuous monitoring.
Integrate secure system life cycle practices, including security requirements definition, SAST, DAST, IAST, RASP, SCA, SBoM review, CI/CD controls, branch protection, and automated testing.
Implement identity, access, authentication, and authorization controls, including SSO, federation, conditional access, identity providers, service providers, RBAC, ABAC, MAC, policy decision points, and policy enforcement points.
Evaluate security operations data to support threat hunting and incident response using OSINT, ISAC intelligence, TIPs, STIX, TAXII, Sigma, YARA, Snort, malware analysis, timeline reconstruction, and root cause analysis.
Training Providers
No providers available for this course yet.
FAQs
General Information
Prerequisites & Requirements
Certification & Exam
Get Custom In-house Training
Post once, get competitive offers from multiple providers. Choose the one that fits your team.
Similar Trainings
EC Council Certified Ethical Hacker Certification (CEH)
The Certified Ethical Hacker (CEH) course teaches participants how to identify and fix security vulnerabilities. Through hands-on labs and theory, learners use attacker tools to test and strengthen network security. The training covers networks , web applications , cloud , mobile , and IoT systems. Participants develop technical skills for security audits and vulnerability assessments. Upon completion, professionals can perform penetration testing and report security gaps to protect systems from exploitation.
EC-Council Certified Penetration Testing Professional (CPENT)
The Certified Penetration Testing Professional (CPENT ) program is the world’s most comprehensive guided penetration testing program. It offers a complete hands-on pentesting methodology and AI techniques mapped to all pentesting phases. CPENT enables you to master pentesting within an enterprise network environment, evaluating intrusion risks and compiling actionable, structured reports. Distinguish yourself with the CPENT , learning beyond technical knowledge, scoping engagements, understanding design, estimating effort, and presenting findings and thrive as a leader in offensive security with versatile skills. CPENT combines guided learning with hands-on practice while immersing you in diverse live scenarios involving IoT systems, segmented networks, and advanced defenses, with practical challenges mapped to each domain. Gain expertise in advanced skills necessary to create your tools, conduct advanced binary exploitation, double pivot, customize scripts, and write your exploits to penetrate the deepest pockets of the network. Hands-on course featuring CTFs, 110+ labs, live cyber ranges, and 50+ tools Practical exam tests skills on unique multi-disciplinary network ranges The only program to teach a complete pen testing methodology
EC-Council Computer Hacking Forensic Investigator (CHFI)
EC-Council’s CHFI program enabled cybersecurity professionals with the knowledge and skills to perform effective digital forensics investigations and accomplish forensic readiness. Master the methodological approach of forensics process, evidence handling procedures, chain-of-custody, acquisition, preservation, analysis, and reporting of digital evidence, legal procedures to ensure it is admissible in court. Build skills beyond traditional hardware and memory forensics and with cloud forensics, mobile and IoT, investigating web application attacks, and malware forensics. CHFI equips you with skills to validate/triage incidents and guide the incident response teams. Build job ready skills on immersive 68 forensic labs Earn globally recognized and demanded by employers Flexible learning options without quitting your current jobs
EC-Council Certified Network Defender (CND) Program
The CND course gives you a full introduction to network security from a defender’s perspective. You learn how to protect, monitor, detect and respond to threats in modern network environments. The training includes theory and hands-on labs , teaching you how to secure networks, configure firewalls and IDS/IPS, monitor traffic, and implement defensive strategies across devices, endpoints, cloud and IoT. The goal is to equip you to build and maintain secure networks for organisations.
EC-Council Certified Cloud Security Engineer (CCSE)
The CCSE course teaches you how to secure, manage and defend cloud environments. You learn both general cloud-security principles and specific skills for major providers such as AWS, Azure and GCP. The training includes hands-on labs, real-world scenarios, and guidance on cloud governance, compliance, monitoring and incident response. This course prepares you to build secure cloud infrastructures , protect data and services in multi-cloud settings , and respond to cloud-specific threats professionally.
EC-Council Certified DevSecOps Engineer (ECDE)
The ECDE course shows you how to combine development, operations and security in a modern workflow. You learn both cloud-native and on-prem security practices, secure coding, infrastructure hardening, automated security tools and continuous deployment pipelines. The training uses many hands-on labs to build real-world DevSecOps skills.