Career Employer

Your FREE SecurityX (CASP+) Flashcards 2026 – 100+ Cards

Realistic, SecurityX (CASP+) exam-style flashcards across all 4 CAS-005 domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer SecurityX (CASP+)”

By

Click Study Flashcards above to open the flashcard hub — hundreds of SecurityX (CASP+) cards you can flip, match, type, or quiz yourself on. Every card is drawn from the four official CAS-005 domains, so you study exactly what the exam tests.[2] Pair them with our free practice test and study guide.

CompTIA SecurityX (CASP+) is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.

SecurityX (CASP+) Flashcard Study Modes

Four modes run on the same 136 cards. Flip is quiet study, one term at a time. Match is a timed term-to-definition game that rewards fast recognition. Type shows the definition and asks you to produce the term, so a front like OCSP has to come out of memory rather than off a list. Quiz turns the same cards into multiple choice.

Free CompTIA SecurityX (CASP+) flashcards from Career Employer — active recall for the CAS-005 exam

Why Flashcards Work for SecurityX (CASP+)

Security Engineering & Cryptography carries 36 cards and the largest share of the exam at 31%, so it is the natural place to spend early sessions. The cards drill algorithm names, protocol choices, and the supporting vocabulary around key handling: RSA and SHA-256 sit next to HMAC, while Salt and Key escrow test whether you can explain a control rather than just recognize the word. IPsec and SFTP cover secure transport.

Security Architecture holds 32 cards against a 27% weight, and the terms lean toward design decisions and deployment models. Expect network segmentation and perimeter ideas such as VLAN and Air gap, modern access and edge concepts including SASE, ZTNA, and SD-WAN, plus cloud service model cards like IaaS and SaaS where the distinction is what the provider manages versus what you manage.

Security Operations also has 32 cards and 22% of the exam. These fronts cover the tooling and the people side of detection and response. SIEM and SOAR test whether you can separate aggregation from automation, Honeypot and Playbook cover deception and repeatable process, and exercise roles show up through Red team, Blue team, and White team. Legal hold pulls in evidence handling.

Governance, Risk & Compliance rounds out the deck with 36 cards and a 20% weight. The terms are frameworks, regulations, and legal standards you must tell apart under pressure: ISO 27001 and ISMS on the management system side, GDPR, HIPAA, and PCI DSS on the regulatory side, CMMI and ITIL as maturity and service management references, and Due care as a liability concept.

SecurityX (CASP+) is dense with terminology — cryptographic primitives, PKI, zero trust and segmentation, the incident-response lifecycle, security teams, and the SLE/ARO/ALE risk formulas.[2] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

SecurityX (CASP+) Flashcards by Domain

The cards are organized by the four official CAS-005 domains. Drill the highest-weighted ones first — Security Engineering and Security Architecture make up nearly 60% of the exam:[2]

SecurityX (CASP+) flashcards by domain and weight
DomainExam weight
Security Engineering & Cryptography31%
Security Architecture27%
Security Operations22%
Governance, Risk, and Compliance20%

How to Get the Most Out of These Flashcards

  • Start heaviest. Open with the 36 cards in Security Engineering & Cryptography; it holds 31% of the exam and shares the largest card count, so early gains there pay off broadest.
  • Type-drill the lookalikes. Run HMAC and OCSP in Type mode until the definitions produce the term instantly, since related crypto acronyms are the easiest ones to confuse under time pressure.
  • Match the architecture acronyms. Use Match for fronts like SASE, ZTNA, and CASB, where the exam expects fast recognition of what each model controls rather than a long explanation.
  • Switch when Quiz stops surprising you. Once Quiz runs clean across Security Operations terms such as SIEM and SOAR, move to the practice test for scenario-length questions the cards cannot simulate.
  • Rotate, do not cram. Work one domain per sitting and cycle all four across the week, so the 136 cards stay in rotation; pair weak fronts with the study guide before returning.

SecurityX (CASP+) Flashcards FAQ

Hundreds of free SecurityX (CASP+) flashcards, organized across all four CAS-005 domains — Security Engineering, Security Architecture, Security Operations, and Governance, Risk, and Compliance. They're free with no account required.

SecurityX (CASP+) flashcard bank

All 136 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Security Engineering & Cryptography (36)

Symmetric encryption
Show answer

Encryption using one shared secret key for both encrypting and decrypting — fast, ideal for bulk data (e.g., AES); the challenge is securely distributing the key.

Asymmetric encryption
Show answer

Encryption using a public/private key pair (e.g., RSA, ECC) — solves key exchange and enables digital signatures, but is slower than symmetric.

AES (Advanced Encryption Standard)
Show answer

The modern, widely trusted symmetric block cipher used for bulk data encryption; supports 128-, 192-, and 256-bit keys.

RSA
Show answer

A widely used asymmetric algorithm based on the difficulty of factoring large numbers; used for key exchange and digital signatures.

Elliptic Curve Cryptography (ECC)
Show answer

Asymmetric cryptography that delivers equivalent strength to RSA with much shorter keys — efficient for mobile and constrained devices.

Diffie-Hellman
Show answer

A key-exchange algorithm that lets two parties derive a shared secret over an insecure channel; the ephemeral variant (DHE/ECDHE) provides forward secrecy.

Cryptographic hash function
Show answer

A one-way function mapping input of any size to a fixed-length, irreversible digest (e.g., SHA-256) — provides integrity, not confidentiality.

SHA-256
Show answer

A secure 256-bit cryptographic hash from the SHA-2 family, used for integrity verification and digital signatures.

HMAC
Show answer

Hash-based Message Authentication Code — a hash combined with a secret key to provide both integrity and authenticity of a message.

Digital signature
Show answer

A value created with a sender's private key that proves authenticity, integrity, and non-repudiation; verified with the sender's public key.

Non-repudiation
Show answer

Assurance that a party cannot deny having performed an action — provided cryptographically by digital signatures.

Salt
Show answer

Random data added to a password before hashing so identical passwords produce different hashes, defeating precomputed (rainbow-table) attacks.

Key stretching
Show answer

Deliberately slow password hashing (bcrypt, PBKDF2, Argon2) that increases the cost of brute-force attacks.

Public Key Infrastructure (PKI)
Show answer

The framework of CAs, RAs, and policies that creates, distributes, validates, and revokes digital certificates binding identities to public keys.

Certificate Authority (CA)
Show answer

The trusted entity in a PKI that signs and issues digital certificates and can revoke them.

Registration Authority (RA)
Show answer

The PKI entity that verifies a requester's identity before the CA issues a certificate.

Digital certificate (X.509)
Show answer

A document binding a verified identity to a public key, signed by a CA so relying parties can trust the key.

Certificate Revocation List (CRL)
Show answer

A published list of certificates a CA has revoked before their natural expiry.

OCSP
Show answer

Online Certificate Status Protocol — a real-time query to check whether a single certificate has been revoked, instead of downloading a full CRL.

Root of trust
Show answer

A trusted anchor (e.g., a root CA or hardware module) from which a chain of trust is built.

Hardware Security Module (HSM)
Show answer

A tamper-resistant device that generates, stores, and uses cryptographic keys inside a hardened boundary; keys never leave in plaintext.

Trusted Platform Module (TPM)
Show answer

A chip embedded in a host for secure boot integrity measurement and hardware-backed key storage.

Key escrow
Show answer

Storing a recoverable copy of cryptographic keys with a trusted third party for business continuity or legal access.

Perfect forward secrecy (PFS)
Show answer

Use of ephemeral session keys so that compromise of a long-term private key cannot decrypt previously recorded sessions.

TLS (Transport Layer Security)
Show answer

The protocol that secures data in transit (e.g., HTTPS) using a hybrid of asymmetric key exchange and symmetric encryption.

SSH (Secure Shell)
Show answer

A protocol providing an encrypted channel for remote login and command execution.

SFTP
Show answer

SSH File Transfer Protocol — secure file transfer running over an SSH-encrypted channel.

IPsec
Show answer

A protocol suite that authenticates and encrypts IP traffic, commonly used to build VPN tunnels.

Post-quantum cryptography (PQC)
Show answer

Algorithms designed to resist attacks by large quantum computers, which could break today's RSA and elliptic-curve cryptography.

Crypto-agility
Show answer

Designing systems so cryptographic algorithms can be swapped out without re-architecting — essential for the post-quantum transition.

“Harvest now, decrypt later”
Show answer

The threat of an adversary recording encrypted traffic today to decrypt it once quantum computers mature.

Homomorphic encryption
Show answer

Encryption that allows computation on ciphertext without decrypting it, so data stays protected during processing.

Brute-force attack
Show answer

An attack that tries every possible key or password until the correct one is found; defeated by large key spaces and key stretching.

Collision (hashing)
Show answer

When two different inputs produce the same hash output; resistance to collisions is why MD5 and SHA-1 are deprecated.

Certificate pinning
Show answer

Hard-coding the expected certificate or public key in a client so it rejects any other, even from a valid CA.

Secure enclave / TEE
Show answer

A trusted execution environment that isolates sensitive code and keys from the main operating system.

Security Architecture (32)

Zero trust
Show answer

A security model that removes implicit trust based on network location and verifies every request on identity, device, and context — “never trust, always verify.”

Verify explicitly
Show answer

The zero-trust tenet of authenticating and authorizing every request on identity, device health, and context — no implicit trust from location.

Assume breach
Show answer

The zero-trust mindset of designing as if an attacker is already inside — segmenting, encrypting, and monitoring to contain damage.

Defense in depth
Show answer

Layering multiple, overlapping controls (data, app, host, network, perimeter, people) so that if one fails, others still protect the asset.

Network segmentation
Show answer

Dividing a network into isolated zones (VLANs, subnets) so traffic between them passes through controls, limiting lateral movement.

Microsegmentation
Show answer

Segmentation pushed down to individual workloads or hosts, enforcing zero-trust policy at a fine granularity.

DMZ (demilitarized zone)
Show answer

A network segment placed between the internal network and untrusted external networks to host public-facing services.

Air gap
Show answer

A physical control that isolates a system or network with no connection to other networks, used for the most sensitive environments.

VLAN
Show answer

A virtual LAN that logically separates devices into broadcast domains regardless of physical location, supporting segmentation.

SASE
Show answer

Secure Access Service Edge — converges networking (SD-WAN) and security (SWG, CASB, ZTNA, FWaaS) into one cloud-delivered service.

ZTNA
Show answer

Zero Trust Network Access — grants application access per session based on identity and policy, instead of broad network access like a VPN.

CASB
Show answer

Cloud Access Security Broker — a policy enforcement point between users and cloud services for visibility, DLP, and access control.

Shared responsibility model
Show answer

The cloud security split where the provider secures the cloud infrastructure and the customer secures their data, identities, and configurations.

IaaS
Show answer

Infrastructure as a Service — the customer secures the most (OS, apps, data); the provider secures the underlying physical and virtualization layers.

SaaS
Show answer

Software as a Service — the provider secures almost everything; the customer mainly secures its data and user access.

Data Loss Prevention (DLP)
Show answer

Monitoring and blocking unauthorized movement of sensitive data across network, endpoint, and storage based on classification.

Data classification
Show answer

Labeling data by sensitivity (e.g., public, internal, confidential, restricted) so the right protections can be applied.

Web Application Firewall (WAF)
Show answer

A control that filters, monitors, and blocks malicious HTTP traffic to and from a web application (layer 7).

Intrusion Prevention System (IPS)
Show answer

Inline monitoring that actively detects and blocks identified threats, unlike an IDS, which only alerts.

Intrusion Detection System (IDS)
Show answer

Monitoring that detects and alerts on suspicious activity but does not block it inline.

Network Access Control (NAC)
Show answer

A control that admits devices to the network only if they meet security policy (patch level, posture, identity).

Virtual Private Network (VPN)
Show answer

An encrypted tunnel that secures data transmission over an unsecured network such as the internet.

Virtualization
Show answer

Running isolated virtual machines on shared hardware via a hypervisor — used to contain and segregate sensitive workloads.

Secure by design
Show answer

Building security into a system from the start rather than bolting it on later.

Attack surface
Show answer

The total set of points where an attacker could attempt to enter or extract data; reducing it is a core architectural goal.

Least functionality
Show answer

Configuring systems to provide only the services and capabilities required, disabling everything else to shrink the attack surface.

High availability (HA)
Show answer

Architecture that minimizes downtime through redundancy, failover, and load balancing.

Containerization
Show answer

Packaging an application with its dependencies into an isolated container; secured via image scanning, least privilege, and runtime controls.

SD-WAN
Show answer

Software-defined WAN — centrally managed, policy-driven wide-area networking, often paired with security in a SASE architecture.

Bastion host
Show answer

A hardened, exposed host that brokers access into a private network, reducing direct exposure of internal systems.

Identity and Access Management (IAM)
Show answer

The discipline and tools for managing digital identities and controlling their access to resources.

Privileged Access Management (PAM)
Show answer

Controls that secure, monitor, and limit the use of privileged/administrator accounts.

Security Operations (32)

SIEM
Show answer

Security Information and Event Management — aggregates and correlates logs across the enterprise to detect threats, alert, and support investigations.

SOAR
Show answer

Security Orchestration, Automation, and Response — automates and coordinates incident response via playbooks and tool integrations.

Security Operations Center (SOC)
Show answer

The team and facility that monitors, detects, and responds to security events around the clock.

Alert fatigue
Show answer

Desensitization caused by too many alerts (often false positives) from an untuned SIEM, leading analysts to miss real threats.

MITRE ATT&CK
Show answer

A knowledge base of real-world adversary tactics (goals) and techniques (methods) used to map detections and drive threat hunting.

Cyber Kill Chain
Show answer

Lockheed Martin's linear 7-stage intrusion model: reconnaissance, weaponization, delivery, exploitation, installation, command & control, actions on objectives.

Indicator of compromise (IoC)
Show answer

A forensic artifact (malicious IP/domain, file hash, registry key, beaconing) that signals a system may have been breached.

Threat hunting
Show answer

The proactive, hypothesis-driven search for adversaries that have evaded existing detections, before any alert fires.

Threat intelligence
Show answer

Evidence-based knowledge about threats — actors, their TTPs, and indicators — used to inform defense.

Honeypot
Show answer

A decoy system designed to lure, detect, and analyze attackers, diverting them from real assets and revealing their techniques.

Red team
Show answer

An offensive security team that emulates real adversaries to find exploitable gaps before attackers do.

Blue team
Show answer

A defensive security team that detects, responds to, and hardens against attacks through the SOC.

Purple team
Show answer

A function that integrates Red and Blue teams so attack findings immediately improve detections.

White team
Show answer

The group that sets the rules of engagement, referees a security exercise, and scores it impartially.

Penetration test
Show answer

An authorized simulated attack that exploits vulnerabilities to assess real-world risk and validate defenses.

Incident response lifecycle
Show answer

NIST's four phases: preparation; detection & analysis; containment, eradication & recovery; post-incident activity.

Containment
Show answer

Limiting the spread and impact of an incident (e.g., isolating a host) — usually the first action in a live incident.

Eradication
Show answer

Removing the threat — malware, attacker footholds, compromised accounts — from the environment.

Chain of custody
Show answer

The documented, unbroken record of who handled evidence and when — what keeps it admissible in legal proceedings.

Order of volatility
Show answer

Collecting evidence most-volatile-first (memory, network state) before less-volatile data (disk) so nothing is lost.

Forensic image
Show answer

A bit-for-bit, hash-verified copy of storage made for analysis so the original evidence is never altered.

Legal hold
Show answer

A directive to preserve relevant data once litigation or an investigation is anticipated.

Root cause analysis
Show answer

Determining the underlying reason an incident occurred so the same issue can be prevented from recurring.

Signature-based detection
Show answer

Detection that matches known patterns (hashes, rules, byte sequences) — precise on known threats but blind to novel ones.

Behavioral analytics
Show answer

Detecting threats by flagging deviations from a baseline of normal user, host, or network behavior.

File Integrity Monitoring (FIM)
Show answer

A control that detects unauthorized changes to critical files by comparing them against a known-good baseline.

Endpoint Detection and Response (EDR)
Show answer

Endpoint tooling that records and analyzes activity to detect, investigate, and respond to threats on hosts.

Vulnerability scanner
Show answer

A tool (e.g., Nessus) that probes systems for known vulnerabilities and misconfigurations.

Dwell time
Show answer

The period an attacker remains undetected in an environment; threat hunting and detection aim to reduce it.

Playbook
Show answer

A predefined, repeatable set of response steps for a given incident type, often automated through SOAR.

Log aggregation
Show answer

Centralizing logs from many sources so they can be correlated and analyzed together (a core SIEM function).

Mean Time to Respond (MTTR)
Show answer

The average time to contain and resolve an incident; lower MTTR signals a more mature operations program.

Governance, Risk & Compliance (36)

Risk appetite
Show answer

The amount and type of risk an organization is willing to accept in pursuit of its objectives, set by leadership.

Risk tolerance
Show answer

The acceptable variation around the risk appetite for a specific objective or activity.

Residual risk
Show answer

The risk that remains after a chosen treatment (mitigate, transfer, accept, avoid) has been applied.

Risk mitigation
Show answer

Reducing a risk's likelihood or impact by applying controls.

Risk transfer
Show answer

Shifting the financial impact of a risk to a third party, such as through insurance or contractual indemnity.

Risk acceptance
Show answer

Choosing to tolerate a risk because it falls within the organization's risk appetite.

Risk avoidance
Show answer

Eliminating a risk by stopping the activity that creates it.

Single Loss Expectancy (SLE)
Show answer

The monetary loss expected from one occurrence of a risk — asset value × exposure factor.

Annualized Rate of Occurrence (ARO)
Show answer

How many times per year a given loss event is expected to occur.

Annualized Loss Expectancy (ALE)
Show answer

SLE × ARO — the expected yearly loss a control's cost is justified against.

Qualitative risk analysis
Show answer

Assessing risk with relative ratings (high/medium/low) rather than precise monetary values.

Quantitative risk analysis
Show answer

Assessing risk with monetary values and probabilities (SLE, ARO, ALE) to justify control spending.

Due diligence
Show answer

The investigation and ongoing evaluation of risk involved in a decision, such as a vendor or acquisition.

Due care
Show answer

The reasonable actions and controls a prudent organization implements based on its due-diligence findings.

Separation of duties
Show answer

Splitting a sensitive task across multiple people so no single person can complete it alone, preventing fraud.

Least privilege
Show answer

Granting each user or process only the minimum access needed to perform its function.

Job rotation
Show answer

Periodically moving staff between roles to surface fraud and reduce dependence on any one person.

Mandatory vacation
Show answer

Requiring staff to take time off so that fraudulent activity dependent on their presence is exposed.

Gap analysis
Show answer

Comparing the current security state against a desired or required state to identify what's missing.

Business Continuity Plan (BCP)
Show answer

A plan to keep critical business functions running during and after a disruption.

Disaster Recovery Plan (DRP)
Show answer

A plan focused on restoring IT systems and data after a disruptive event — a key component of a BCP.

RTO (Recovery Time Objective)
Show answer

The maximum acceptable time to restore a system or process after a disruption.

RPO (Recovery Point Objective)
Show answer

The maximum acceptable amount of data loss, measured as time, after a disruption.

ISMS
Show answer

Information Security Management System — the policies and processes (e.g., per ISO 27001) that manage information-security risk.

ISO 27001
Show answer

An international standard specifying requirements for establishing and operating an ISMS.

NIST Cybersecurity Framework
Show answer

A voluntary framework organizing cybersecurity activities into core functions (Identify, Protect, Detect, Respond, Recover, Govern).

GDPR
Show answer

General Data Protection Regulation — the EU law protecting the privacy and personal data of EU residents.

PCI DSS
Show answer

Payment Card Industry Data Security Standard — requirements for protecting cardholder data.

HIPAA
Show answer

U.S. regulation protecting the privacy and security of health information.

CMMI
Show answer

Capability Maturity Model Integration — a model for assessing and improving the maturity of organizational processes.

ITIL
Show answer

A framework of best practices for delivering IT services effectively and efficiently.

Data Protection Officer (DPO)
Show answer

A role responsible for overseeing an organization's compliance with data-protection laws such as GDPR.

Third-party / vendor risk assessment
Show answer

Evaluating a vendor's security posture and compliance before and during a business relationship.

Software Bill of Materials (SBOM)
Show answer

A machine-readable inventory of every component and dependency in software, key to managing supply-chain risk.

Risk register
Show answer

A documented record of identified risks, their assessment, owners, and treatment status.

Compensating control
Show answer

An alternative safeguard used when the primary control cannot be applied, to reduce residual risk.

References

  1. 1.CompTIA. “CompTIA SecurityX (CASP+) Certification.” comptia.org. ↑
  2. 2.CompTIA. “SecurityX (CAS-005) Exam Objectives.” comptia.org. ↑
  3. 3.National Institute of Standards and Technology. “SP 800-207, Zero Trust Architecture.” csrc.nist.gov. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.