CySA+: analysis and response in production
Six lessons, 35 questions, and five cases on event analysis, vulnerabilities, SOC AI, incident response, and communication.
Objectives and progression
Initial course with six lessons and 40 original decisions in fictional APS, SOC, and IT-project scenarios. Internal assessment of 23 decisions in 55 minutes. Uses the official V4 objectives summary; reconciliation with the detailed final PDF, SIEM/EDR labs, packet analysis, and practical performance need further depth. Preparation for CySA+ V4 / CS0-004, launched 2026-06-23. The current version is published in English; other announced languages are not yet available according to the page consulted on 2026-09-30..
Audience: Security analysts, APS professionals, and technical coordinators collaborating on response and vulnerability management.
Prerequisites: Networking, systems, and security basics. CompTIA recommends around four years of relevant experience; this recommendation is not a mandatory certification prerequisite.
305 estimated study minutes
- Interpret events in context and test hypotheses with evidence.
- Use assistance and workflows with boundaries, traceability, and recovery.
- Distinguish valid results, assessment gaps, and false positives.
- Combine severity, exploitation, exposure, and operational impact.
- Coordinate response and evidence with service-return criteria.
- Communicate impact, uncertainty, and progress using interpretable measures.
Modules
- Telemetry, identity, and hunting
- AI and automation in security operations
- Assess vulnerabilities and coverage
- Prioritize risk and establish remediation
- Contain, preserve, and recover
- Reporting, metrics, and handover
Continue learning
References and version
CS0-004 / CySA+ V4, launched 2026-06-23
- CySA+ V4 exam facts and objectives summary · 2026-09-30
- CySA+ V3 language-specific retirement notice · 2026-09-30
- Incident response within cybersecurity risk management · 2026-09-30
- Integrating forensic techniques into incident response · 2026-09-30
- Security testing and assessment · 2026-09-30
- Enterprise patch management planning · 2026-09-30
- Using EPSS · 2026-09-30
- CVSS v4.0 user guide · 2026-09-30
- Known Exploited Vulnerabilities catalog · 2026-09-30
- Traffic Light Protocol · 2026-09-30
- Valid Accounts technique · 2026-09-30
- Entra sign-in log categories · 2026-09-30
- Sysmon event semantics · 2026-09-30
- Logging cheat sheet · 2026-09-30
- Sentinel response automation · 2026-09-30
- Security backporting practice · 2026-09-30
- Prompt injection risks and controls · 2026-09-30
- Misinformation and overreliance · 2026-09-30
- Sensitive information disclosure · 2026-09-30
- HTTP semantics and Retry-After · 2026-09-30
- Additional HTTP status codes including 429 · 2026-09-30
What you will explore
0 / 6Telemetry, identity, and hunting
Interpret events in context and test hypotheses with evidence.
AI and automation in security operations
Use assistance and workflows with boundaries, traceability, and recovery.
Assess vulnerabilities and coverage
Distinguish valid results, assessment gaps, and false positives.
Prioritize risk and establish remediation
Combine severity, exploitation, exposure, and operational impact.
Contain, preserve, and recover
Coordinate response and evidence with service-return criteria.
Reporting, metrics, and handover
Communicate impact, uncertainty, and progress using interpretable measures.