CompTIA exam preparation
CompTIA SecurityX
Follow a topic roadmap built from the published exam blueprint, with lessons, practice exercises in a real terminal and practice exams.
An advanced cybersecurity certification validating the skills of security architects and senior security engineers to design, build, and implement secure enterprise solutions.
What you'll learn
Every objective SecurityX publishes, and what it asks you to be able to do. The percentage is how much of the exam each one is worth.
- Governance, risk, and compliance (20% of the exam)Security program documentation : policies, procedures, standards, and guidelines. Program management : training (phishing, security, privacy), communication, reporting, and RACI matrix. Frameworks : COBIT, ITIL, etc. Configuration management : asset life cycle, CMDB, and inventory. Data governance : production, development, testing, and QA. Risk management : impact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability. And 5 more, each a topic in the course below.
- Security architecture (27% of the exam)Network architecture : segmentation, microsegmentation, VPN, always-on VPN, and API integration. Security boundaries : asset identification, management, attestation, data perimeters, and secure zones. Deperimeterization : SASE, SD-WAN, and software-defined networking. Zero trust concepts : defining subject-object relationships. Cloud data security : data exposure, leakage, remanence, insecure storage, and encryption keys. Cloud capabilities : CASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads. And 1 more, each a topic in the course below.
- Security engineering (31% of the exam)Cryptographic techniques : tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography. Advanced cryptography : PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration. Cryptographic use cases : data at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication. Automation : scripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation. Vulnerability management : scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS).
- Security operations (22% of the exam)Monitoring and data analysis : SIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users). Vulnerabilities and attack surface : injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth. Threat hunting : internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort). Incident response : malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis.
The exam at a glance
- Length
- 165 minutes
- Valid for
- 3 years
- Style
- Hands-on
maximum of 90 a mix of multiple-choice and performance-based questions. Based on V5. Pass mark is pass/fail only; no scaled score.
minimum of 10 years of general hands-on IT experience including 5 years of hands-on security with Network+ Security+ CySA+ Cloud+ and PenTest+ or equivalent knowledge
Sitting the exam
The part nobody publishes in a syllabus. For SecurityX the logistics are study strategy: what you are allowed to read while the clock runs changes how you should practise, and what a second attempt costs changes when you should book.
Where you sit it
- Candidates may complete the CompTIA SecurityX exam via the internet or at a designated testing location.
What you are asked
- The assessment contains a maximum of 90 questions consisting of a combination of multiple-choice and performance-based items.
- The maximum testing time permitted is 165 minutes.
How it is marked
- The grading system is strictly pass or fail without any scaled score.
If you do not pass
- Every exam voucher alongside any retakes remains valid for 12 months starting from the purchase date.
What comes with it
- The certification kit features a professionally printed 8.5 x 11" frameable certificate.
Read off the official exam page on 9 September 2026. Rules change without notice, so confirm anything you are about to spend money on.
What the exam covers
Straight from the published curriculum. The weights are how much of the exam each area is worth, so they are the honest guide to where your study time should go.
Course content
44 topics
1. Security Foundations and Documentation
Core security documentation structures and their relationships
2. Security Program Documentation
- Security program documentation : policies, procedures, standards, and guidelines.
3. Security Program Management
- Program management : training (phishing, security, privacy), communication, reporting, and RACI matrix.
4. Governance and IT Service Frameworks
- Frameworks : COBIT, ITIL, etc.
5. Configuration and Asset Management
- Configuration management : asset life cycle, CMDB, and inventory.
6. Data Governance
- Data governance : production, development, testing, and QA.
7. Risk Management Core Concepts
- Risk management : impact analysis, risk assessment (quantitative vs. qualitative), third-party risk, confidentiality, integrity, and availability.
8. Risk Assessment Methods
Quantitative and qualitative risk assessment methodologies
9. Threat Actors and Attack Patterns
- Threat modeling : actor characteristics, attack patterns, and frameworks (ATT&CK, CAPEC, STRIDE).
10. Threat Modeling Frameworks
Threat modeling frameworks including ATT&CK, CAPEC, and STRIDE
11. Attack Surface Analysis
- Attack surface : architecture reviews, data flows, and trust boundaries.
12. Compliance Strategies
- Compliance strategies : industry-specific standards (PCI DSS, ISO/IEC 27000).
13. Security Frameworks
- Security frameworks : NIST, CSF, CSA, and others.
14. GRC Tools and Automation
- GRC tools: mapping, automation, and compliance tracking.
15. Cryptographic Fundamentals
Basic cryptographic concepts and symmetric/asymmetric encryption
16. Cryptographic Techniques
- Cryptographic techniques : tokenization, code signing, cryptographic erase, digital signatures, hashing, and symmetric/asymmetric cryptography.
17. Post-Quantum and Key Management
- Advanced cryptography : PQC, key stretching, homomorphic encryption, forward secrecy, and hardware acceleration.
18. Specialized Cryptographic Techniques
Homomorphic encryption and hardware acceleration for cryptography
19. Cryptographic Use Cases
- Cryptographic use cases : data at rest, in transit, and in use; secure email, blockchain, privacy, compliance, and certificate-based authentication.
20. Network Security Architecture
- Network architecture : segmentation, microsegmentation, VPN, always-on VPN, and API integration.
21. Security Boundaries and Asset Control
- Security boundaries : asset identification, management, attestation, data perimeters, and secure zones.
22. Deperimeterization Technologies
- Deperimeterization : SASE, SD-WAN, and software-defined networking.
23. Zero Trust Architecture
- Zero trust concepts : defining subject-object relationships.
24. Cloud Security Fundamentals
Shared responsibility model and cloud security basics
25. Cloud Data Security
- Cloud data security : data exposure, leakage, remanence, insecure storage, and encryption keys.
26. Cloud Access Security Broker and Shadow IT
- Cloud capabilities : CASB (API-based, proxy-based), shadow IT detection, shared responsibility model, CI/CD pipeline, Terraform, Ansible, container security, orchestration, and serverless workloads.
27. Cloud DevOps Security
CI/CD pipeline security, Terraform, and Ansible for cloud infrastructure
28. Cloud Workload Security
Container security, orchestration, and serverless workload protection
29. Cloud Control Strategies
- Cloud control strategies : proactive, detective, and preventative controls; customer-to-cloud connectivity, service integration, and continuous authorization.
30. Security Scripting Fundamentals
PowerShell, Bash, and Python for security automation
31. Security Automation Foundations
- Automation : scripting (PowerShell, Bash, Python), event triggers, IaC, cloud APIs, generative AI, containerization, patching, SOAR, and workflow automation.
32. Security Orchestration and Workflow
SOAR platforms and workflow automation for security operations
33. Vulnerability Scanning and Reporting
- Vulnerability management : scanning, reporting, and SCAP (OVAL, XCCDF, CPE, CVE, CVSS).
34. SCAP Standards and Protocols
SCAP framework components: OVAL, XCCDF, and CPE
35. SIEM Fundamentals
- Monitoring and data analysis : SIEM (event parsing, retention, false positives/negatives), aggregate analysis (correlation, prioritization, trends), and behavior baselines (network, systems, users).
36. Security Analytics and Baselines
Correlation analysis and behavior baselines for security monitoring
37. Common Vulnerabilities
- Vulnerabilities and attack surface : injection, XSS, insecure configurations, outdated software, and weak ciphers; mitigations include input validation, patching, encryption, and defense-in-depth.
38. Vulnerability Mitigations
Input validation and defense-in-depth strategies for vulnerability mitigation
39. Internal Threat Intelligence
- Threat hunting : internal intelligence (honeypots, UBA), external intelligence (OSINT, dark web, ISACs), TIPs, IoC sharing (STIX, TAXII), and rule-based languages (Sigma, YARA, Snort).
40. External Threat Intelligence
OSINT, dark web intelligence, and ISACs for external threat intelligence
41. Threat Intelligence Sharing
IoC sharing with STIX and TAXII protocols
42. Threat Detection Rule Languages
Rule-based detection languages: Sigma, YARA, and Snort
43. Malware Analysis
- Incident response : malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery, and root cause analysis.
44. Incident Investigation and Recovery
Reverse engineering and root cause analysis for incident response
What to know before you start
- General hands-on IT experience
- Hands-on security experience
- Network principles
- Security principles
- Cybersecurity analysis
- Cloud concepts
- Penetration testing
Other certifications
Frequently asked questions
How long is the SecurityX exam and what does it cost?
165 minutes, fee on comptia's site. maximum of 90 a mix of multiple-choice and performance-based questions. The certification stays valid for 3 years.
What is on the SecurityX exam?
4 domains. The heaviest is Security engineering at 31% of the exam, so it is the one worth over-preparing.
What should I know before starting SecurityX?
General hands-on IT experience. Hands-on security experience. Network principles. Security principles. Cybersecurity analysis. Cloud concepts. Penetration testing.
Is the SecurityX exam hands-on?
Yes. It is performance-based: you are given a live environment and a command line, and marked on what you actually do rather than what you can recognise. Reading alone does not prepare you for it.
Exam details from CompTIA, checked August 2026. Always confirm on their page before booking.
What learners say about Acelro
About Acelro rather than the SecurityX exam: what learners made of the gap analysis, the roadmap and the projects.
“The roadmap makes me focus on a learning curve, no matter the length.”
“Acelro has been really great for me, an inspiring experience. I've gained a lot of confidence doing projects I thought were rocket science.”
“The gap analysis maps your actual skills against what the current job market is asking for. Nobody else made it that clear where I stood.”