Skip to main content

CompTIA exam preparation

CompTIA SecurityX

Follow a topic roadmap built from the published exam blueprint, with lessons, practice exercises in a real terminal and practice exams.

An advanced cybersecurity certification validating the skills of security architects and senior security engineers to design, build, and implement secure enterprise solutions.

Lessons, quizzes and hands-on practice across every SecurityX objective, added to your roadmap. Free account.
Not ready to start? Tell us you want it and nothing else changes.

What you'll learn

Every objective SecurityX publishes, and what it asks you to be able to do. The percentage is how much of the exam each one is worth.

  • Governance, risk, and compliance (20% of the exam)Security program documentation : policies, procedures, standards, and guidelines. Program management : training (phishing, security, privacy), communication, reporting, and RACI matrix. Frameworks : COBIT, ITIL, etc. Configuration management : asset life cycle, CMDB, and inventory. Data governance : production, development, testing, and QA. Risk management : impact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability. And 5 more, each a topic in the course below.
  • Security architecture (27% of the exam)Network architecture : segmentation, microsegmentation, VPN, always-on VPN, and API integration. Security boundaries : asset identification, management, attestation, data perimeters, and secure zones. Deperimeterization : SASE, SD-WAN, and software-defined networking. Zero trust concepts : defining subject-object relationships. Cloud data security : data exposure, leakage, remanence, insecure storage, and encryption keys. Cloud capabilities : CASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads. And 1 more, each a topic in the course below.
  • Security engineering (31% of the exam)Cryptographic techniques : tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography. Advanced cryptography : PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration. Cryptographic use cases : data at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication. Automation : scripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation. Vulnerability management : scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS).
  • Security operations (22% of the exam)Monitoring and data analysis : SIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users). Vulnerabilities and attack surface : injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth. Threat hunting : internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort). Incident response : malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis.

The exam at a glance

Length
165 minutes
Valid for
3 years
Style
Hands-on

maximum of 90 a mix of multiple-choice and performance-based questions. Based on V5. Pass mark is pass/fail only; no scaled score.

minimum of 10 years of general hands-on IT experience including 5 years of hands-on security with Network+ Security+ CySA+ Cloud+ and PenTest+ or equivalent knowledge

Sitting the exam

The part nobody publishes in a syllabus. For SecurityX the logistics are study strategy: what you are allowed to read while the clock runs changes how you should practise, and what a second attempt costs changes when you should book.

Where you sit it

  • Candidates may complete the CompTIA SecurityX exam via the internet or at a designated testing location.

What you are asked

  • The assessment contains a maximum of 90 questions consisting of a combination of multiple-choice and performance-based items.
  • The maximum testing time permitted is 165 minutes.

How it is marked

  • The grading system is strictly pass or fail without any scaled score.

If you do not pass

  • Every exam voucher alongside any retakes remains valid for 12 months starting from the purchase date.

What comes with it

  • The certification kit features a professionally printed 8.5 x 11" frameable certificate.

Read off the official exam page on 9 September 2026. Rules change without notice, so confirm anything you are about to spend money on.

What the exam covers

Straight from the published curriculum. The weights are how much of the exam each area is worth, so they are the honest guide to where your study time should go.

Governance, risk, and compliance20%
Security architecture27%
Security engineering31%
Security operations22%

Course content

44 topics

Core security documentation structures and their relationships

  • Security program documentation : policies, procedures, standards, and guidelines.
  • Program management : training (phishing, security, privacy), communication, reporting, and RACI matrix.
  • Frameworks : COBIT, ITIL, etc.
  • Configuration management : asset life cycle, CMDB, and inventory.
  • Data governance : production, development, testing, and QA.
  • Risk management : impact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability.

Quantitative and qualitative risk assessment methodologies

  • Threat modeling : actor characteristics, attack patterns, and frameworks (ATT&CK, CAPEC, STRIDE).

Threat modeling frameworks including ATT&CK, CAPEC, and STRIDE

  • Attack surface : architecture reviews, data flows, and trust boundaries.
  • Compliance strategies : industry-specific standards (PCI DSS, ISO/IEC 27000).
  • Security frameworks : NIST, CSF, CSA, and others.
  • GRC tools: mapping, automation, and compliance tracking.

Basic cryptographic concepts and symmetric/asymmetric encryption

  • Cryptographic techniques : tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography.
  • Advanced cryptography : PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration.

Homomorphic encryption and hardware acceleration for cryptography

  • Cryptographic use cases : data at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication.
  • Network architecture : segmentation, microsegmentation, VPN, always-on VPN, and API integration.
  • Security boundaries : asset identification, management, attestation, data perimeters, and secure zones.
  • Deperimeterization : SASE, SD-WAN, and software-defined networking.
  • Zero trust concepts : defining subject-object relationships.

Shared responsibility model and cloud security basics

  • Cloud data security : data exposure, leakage, remanence, insecure storage, and encryption keys.
  • Cloud capabilities : CASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads.

CI/CD pipeline security, Terraform, and Ansible for cloud infrastructure

Container security, orchestration, and serverless workload protection

  • Cloud control strategies : proactive, detective, and preventative controls; customer-to-cloud connectivity, service integration, and continuous authorization.

PowerShell, Bash, and Python for security automation

  • Automation : scripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation.

SOAR platforms and workflow automation for security operations

  • Vulnerability management : scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS).

SCAP framework components: OVAL, XCCDF, and CPE

  • Monitoring and data analysis : SIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users).

Correlation analysis and behavior baselines for security monitoring

  • Vulnerabilities and attack surface : injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth.

Input validation and defense-in-depth strategies for vulnerability mitigation

  • Threat hunting : internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort).

OSINT, dark web intelligence, and ISACs for external threat intelligence

IoC sharing with STIX and TAXII protocols

Rule-based detection languages: Sigma, YARA, and Snort

  • Incident response : malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis.

Reverse engineering and root cause analysis for incident response

What to know before you start

  • General hands-on IT experience
  • Hands-on security experience
  • Network principles
  • Security principles
  • Cybersecurity analysis
  • Cloud concepts
  • Penetration testing

Other certifications

Frequently asked questions

How long is the SecurityX exam and what does it cost?

165 minutes, fee on comptia's site. maximum of 90 a mix of multiple-choice and performance-based questions. The certification stays valid for 3 years.

What is on the SecurityX exam?

4 domains. The heaviest is Security engineering at 31% of the exam, so it is the one worth over-preparing.

What should I know before starting SecurityX?

General hands-on IT experience. Hands-on security experience. Network principles. Security principles. Cybersecurity analysis. Cloud concepts. Penetration testing.

Is the SecurityX exam hands-on?

Yes. It is performance-based: you are given a live environment and a command line, and marked on what you actually do rather than what you can recognise. Reading alone does not prepare you for it.

Exam details from CompTIA, checked August 2026. Always confirm on their page before booking.

What learners say about Acelro

About Acelro rather than the SecurityX exam: what learners made of the gap analysis, the roadmap and the projects.

The roadmap makes me focus on a learning curve, no matter the length.
Daniel O., Career path navigation
Acelro has been really great for me, an inspiring experience. I've gained a lot of confidence doing projects I thought were rocket science.
Stephanie E., Learner
The gap analysis maps your actual skills against what the current job market is asking for. Nobody else made it that clear where I stood.
Cebuka B., Career changer

Not sure you are ready for SecurityX yet? Check where your skills stand in under a minute, no sign-up required.