Every Exam PrepFREE EXAM PREP
Ask AI
STUDY GUIDE · COMPTIA CYSA+

CompTIA Cybersecurity Analyst+ (CySA+) Study Guide

Verified against the CompTIA exam objectives 6 sections
Written by Every Exam Prep Editorial TeamSource and review policyPublished July 18, 2026
Questions
85
Time limit
2h 45m
Passing score
750 (on a scale of 100-900)
Governing body
CompTIA

CompTIA Cybersecurity Analyst+ (CySA+) is a vendor-neutral, intermediate-level certification built around the day-to-day work of a security operations team. Rather than testing broad IT fundamentals, it focuses on the analyst's core job: watching for threats, making sense of security data, and acting on what it reveals.

Who It's For

CySA+ is designed for professionals working in a Security Analyst role, including those in security operations centers (SOCs), threat intelligence teams, and vulnerability management functions. It sits between entry-level certifications like Security+ and more specialized, advanced credentials, making it a natural next step for IT professionals who want to move into a hands-on defensive security career.

Why It Matters

  • Demonstrates practical, job-ready skills rather than purely theoretical knowledge.
  • Signals to employers that a candidate can operate real security tooling and processes, not just recite concepts.
  • Often referenced in job postings for SOC analyst, threat intelligence analyst, and incident response roles.
  • Builds a foundation for progressing toward more advanced offensive or defensive security certifications later in a career path.

For employers, hiring someone with CySA+ offers a level of assurance that the candidate understands how to detect anomalies, interpret log and network data, and participate meaningfully in an incident response process — skills that are difficult to verify from a resume alone.

Understanding the exam's structure ahead of time removes a lot of test-day uncertainty. CySA+ (exam code CS0-003) follows CompTIA's standard testing model but with its own specific limits and scoring.

Format and Timing

  • The exam contains a maximum of 85 questions.
  • Candidates are given 165 minutes to complete it.
  • Questions are a mix of multiple-choice and performance-based items, meaning some questions require working through a simulated scenario rather than simply picking an answer.

Passing Score

A passing score is 750, measured on a scale that runs from 100 to 900. Because the scale isn't a simple percentage, it's worth treating 750 as the target rather than trying to estimate raw questions answered correctly.

Delivery

Pearson VUE is the official test delivery provider for CompTIA exams, including CySA+. Candidates can take the exam at a physical test center or through Pearson VUE's online proctored option (OnVUE), which allows the exam to be taken remotely under webcam supervision.

After Certification

Once earned, the CySA+ certification is valid for three years from the certification date. Certification holders can renew through Continuing Education Units (CEUs) rather than retaking the exam from scratch, which rewards professionals who stay active in ongoing training and industry involvement.

CySA+ is organized around the practical lifecycle of security operations work: gathering and interpreting data, identifying weaknesses, responding to incidents, and supporting the reporting and governance side of a security program. While exact domain weightings can shift between exam versions, the exam consistently covers the following conceptual areas.

Security Operations

This area centers on the daily work of a security analyst — monitoring systems, analyzing logs and alerts, using threat intelligence to understand attacker behavior, and applying security tools to detect suspicious activity across networks, endpoints, and cloud environments.

Vulnerability Management

Candidates are expected to understand how to identify, prioritize, and manage vulnerabilities across an organization's infrastructure — including interpreting vulnerability scan results, understanding common attack vectors, and recommending remediation steps appropriate to business risk.

Incident Response and Management

This covers the analyst's role once an incident is detected: containment, eradication, and recovery steps, as well as how to apply an incident response process consistently and communicate findings to relevant stakeholders.

Reporting and Communication

Security analysts don't just detect and respond — they also have to explain what happened. This area focuses on translating technical findings into reports, supporting compliance and governance requirements, and communicating risk in a way that non-technical stakeholders can act on.

Together, these areas reflect a realistic SOC workflow: watch, assess, act, and report — which is why hands-on familiarity with security tools matters as much as memorizing terminology.

CySA+ rewards hands-on familiarity more than rote memorization, so a study plan should balance conceptual review with active practice using logs, alerts, and simulated tools. A six-to-eight week plan works well for most working professionals studying part-time.

Weeks 1-2: Build the Foundation

  • Review core security operations concepts: log analysis, network monitoring, and common attack techniques.
  • Get comfortable with the terminology and tools analysts use daily, even if you don't have hands-on access to all of them.
  • Take an initial practice assessment to identify weak areas early, rather than waiting until the end of your prep.

Weeks 3-4: Vulnerability Management and Threat Intelligence

  • Study how vulnerability scans are interpreted and prioritized.
  • Learn how threat intelligence feeds into detection and response decisions.
  • Practice reading sample scan outputs and alerts to build pattern recognition.

Weeks 5-6: Incident Response and Reporting

  • Walk through the stages of incident response repeatedly until the sequence becomes second nature.
  • Practice writing short incident summaries — this mirrors the reporting skills the exam tests.
  • Review governance and compliance basics that tie into reporting requirements.

Final Week: Practice and Review

  • Focus heavily on performance-based question practice, since these simulate real analyst tasks rather than simple recall.
  • Revisit weak domains identified in earlier practice sessions.
  • Do a final review pass rather than cramming new material close to test day.

Because the exam blends multiple-choice with performance-based scenarios, spending real time working through simulated tasks — not just reading — pays off disproportionately.

Before the Exam

  • Confirm your delivery method in advance — whether you're testing at a physical center or through online proctoring, arrive early or complete system checks well before your scheduled time.
  • Get a full night's sleep rather than cramming late; recognizing patterns in logs and alerts requires a clear head more than last-minute memorization.
  • Review your weakest domain one final time, but avoid trying to absorb entirely new material the day before.

During the Exam

  • Budget your time deliberately across 165 minutes — performance-based questions tend to take longer, so consider tackling multiple-choice questions first if the exam interface allows flagging and revisiting.
  • Read scenario-based questions carefully; CySA+ often tests judgment about the most appropriate next action, not just factual recall.
  • Don't overthink performance-based simulations — apply the same logical process you would use on the job, working step by step rather than searching for a trick.
  • Flag uncertain questions and return to them rather than getting stuck early and running short on time.

Common Mistakes to Avoid

  • Treating the exam like a pure memorization test — CySA+ is scenario-heavy, so understanding "why" matters more than memorizing lists.
  • Skipping hands-on practice with logs, alerts, or scan output because it feels less efficient than reading — this is often where candidates lose the most points.
  • Underestimating the reporting and communication content, which is easy to overlook compared to more technical domains but still counts toward the passing score.
  • Waiting until the final days to attempt full-length practice exams under timed conditions.

Because CySA+ leans heavily on applied scenarios rather than pure memorization, the most useful preparation resources are the ones that let you practice recognizing patterns and recalling terminology quickly under pressure.

Practice Questions

Working through practice questions modeled on the exam's scenario style helps build the judgment CySA+ actually tests — choosing the most appropriate next action in a security operations context, not just identifying a correct definition. Repeated exposure to this question style also helps with time management, since it trains you to read scenarios efficiently.

Flashcards

Flashcards are well suited for the vocabulary-heavy parts of the exam: tool names, attack techniques, frameworks, and process terminology that show up repeatedly across different domains. Short, frequent review sessions using flashcards can reinforce recall without requiring long blocks of dedicated study time.

Glossary

A glossary of key terms is useful as a quick reference while working through practice questions or reviewing study notes, especially for candidates newer to security operations who are still building fluency with the field's terminology. Keeping a glossary on hand reduces the friction of stopping to look up unfamiliar terms mid-study session.

Used together, these resource types support both the conceptual and applied sides of exam prep — building vocabulary fluency while also rehearsing the scenario-based thinking that CySA+ emphasizes.

CompTIA CySA+ flashcards

30 cards on the highest-yield terms and rules. Grading uses spaced repetition and saves in this browser.

Card 1 of 300 mastered
Say the answer out loud before flipping.
Browse all 30 cards
  1. What four domains make up the CySA+ (CS0-003) exam objectives?

    Security Operations; Vulnerability Management; Incident Response and Management; and Reporting and Communication.

  2. What is the primary goal of threat intelligence in security operations?

    To collect, process, and analyze data about adversary capabilities, infrastructure, and intent so defenders can proactively adjust controls and detection rather than react blindly.

  3. What does the Cyber Kill Chain describe?

    A sequential model of attacker stages — reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives — used to identify where defenses can interrupt an attack.

  4. How does the MITRE ATT&CK framework differ from the Cyber Kill Chain?

    ATT&CK is a matrix of real-world adversary tactics and techniques organized by objective (not strict sequence), giving defenders granular, mappable behaviors for detection and threat modeling rather than a linear phase model.

  5. What is a false positive in security monitoring?

    An alert that indicates malicious or anomalous activity when none actually occurred, wasting analyst time and potentially causing alert fatigue.

  6. What is a false negative and why is it dangerous?

    A real threat or malicious event that fails to trigger an alert; it's dangerous because the attack goes undetected and unaddressed.

  7. What is the purpose of a SIEM?

    A Security Information and Event Management platform aggregates, normalizes, and correlates log data from many sources to enable centralized detection, alerting, and investigation.

  8. What does SOAR add beyond a SIEM?

    Security Orchestration, Automation, and Response tools automate repetitive investigation and remediation steps (playbooks) and orchestrate actions across multiple security tools, reducing analyst workload and response time.

  9. What is the difference between a vulnerability scan and a penetration test?

    A vulnerability scan is an automated, non-intrusive process that identifies known weaknesses; a penetration test actively exploits weaknesses to demonstrate real-world impact, typically performed manually or semi-manually.

  10. What is CVSS used for?

    The Common Vulnerability Scoring System provides a standardized numeric score (0-10) reflecting a vulnerability's severity based on exploitability and impact metrics, helping prioritize remediation.

  11. What is the difference between CVE and CWE?

    A CVE (Common Vulnerabilities and Exposures) identifies a specific, publicly disclosed vulnerability instance; a CWE (Common Weakness Enumeration) categorizes the underlying type of software weakness (e.g., buffer overflow) that can lead to vulnerabilities.

  12. What is credentialed vs. non-credentialed vulnerability scanning?

    Credentialed scans authenticate to the target to inspect it from the inside for deeper, more accurate results; non-credentialed scans probe from the outside without login access, similar to what an external attacker would see.

  13. What is risk in the context of vulnerability management, expressed as a formula?

    Risk is generally understood as a function of threat, vulnerability, and impact (or likelihood x impact) — the potential for loss when a threat exploits a vulnerability affecting an asset.

  14. What is the purpose of a compensating control?

    An alternative safeguard used when the primary or recommended control cannot be implemented, providing similar risk reduction through other means.

  15. What are the phases of the incident response lifecycle (NIST-based)?

    Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity (lessons learned).

  16. What is the difference between containment, eradication, and recovery?

    Containment limits the spread/impact of an incident; eradication removes the root cause (malware, backdoors, compromised accounts); recovery restores affected systems to normal, verified-clean operation.

  17. What is chain of custody in digital forensics?

    Documented, unbroken record of who collected, handled, and had access to evidence, ensuring its integrity and admissibility for legal or disciplinary proceedings.

  18. What is order of volatility?

    A prioritized sequence for collecting digital evidence starting with the most volatile (CPU registers, cache, RAM) and ending with the least volatile (disk, backups, documentation), to avoid losing evidence during acquisition.

  19. What is the purpose of a legal hold in incident response?

    A directive to preserve all potentially relevant data and evidence because litigation, investigation, or regulatory action is anticipated, preventing normal deletion or overwriting.

  20. What distinguishes an IOC (Indicator of Compromise) from an IOA (Indicator of Attack)?

    An IOC is forensic evidence that a compromise already happened (e.g., a malicious hash or IP); an IOA reflects the attacker's intent or behavior in progress, enabling detection before the compromise completes.

  21. What is a playbook in incident response?

    A predefined, step-by-step procedure for responding to a specific type of incident (e.g., ransomware, phishing) that ensures consistent, repeatable, and efficient handling.

  22. What is the difference between qualitative and quantitative risk assessment?

    Qualitative assessment ranks risks using descriptive scales (low/medium/high); quantitative assessment assigns numeric/monetary values (e.g., using ALE, SLE, ARO) to express risk in financial terms.

  23. What do SLE, ARO, and ALE represent in quantitative risk analysis?

    Single Loss Expectancy (cost of one incident), Annualized Rate of Occurrence (expected frequency per year), and Annualized Loss Expectancy (SLE x ARO), used to estimate yearly financial risk exposure.

  24. What is threat hunting?

    A proactive, analyst-driven search through networks and systems to detect threats that have evaded existing automated security controls, often based on hypotheses derived from threat intelligence.

  25. What is the difference between an IDS and an IPS?

    An Intrusion Detection System passively monitors and alerts on suspicious traffic without blocking it; an Intrusion Prevention System sits inline and can actively block or drop malicious traffic in real time.

  26. What is a UEBA solution used for?

    User and Entity Behavior Analytics establishes behavioral baselines for users and devices and flags anomalies (e.g., unusual login times, data access patterns) that may indicate compromised credentials or insider threats.

  27. What is the purpose of network segmentation as a security control?

    Dividing a network into isolated zones limits an attacker's ability to move laterally and contains the blast radius of a compromise to a smaller portion of the environment.

  28. What is a Software Bill of Materials (SBOM)?

    An inventory listing all components, libraries, and dependencies within a piece of software, used to identify supply-chain risk and quickly determine exposure when a component vulnerability is disclosed.

  29. What is the goal of attack surface management?

    Continuously discovering, inventorying, and reducing all points (assets, services, exposed interfaces) where an attacker could potentially gain entry to an environment.

  30. What is the difference between EDR and traditional antivirus?

    Traditional antivirus primarily relies on signature matching to block known malware; Endpoint Detection and Response continuously monitors endpoint behavior, enables investigation, and supports active response actions like isolation.

CompTIA CySA+ glossary

25 terms the CompTIA CySA+ tests, defined in plain English.

Attack Surface
The complete set of points — systems, services, accounts, interfaces — through which an unauthorized party could attempt to gain access to an environment.
Chain of Custody
A documented record tracking who collected, accessed, and handled a piece of digital evidence, preserving its integrity for potential legal use.
CVE
Common Vulnerabilities and Exposures; a publicly maintained, uniquely identified catalog entry for a specific known software or hardware vulnerability.
CVSS
Common Vulnerability Scoring System; a standardized framework that produces a numeric severity score for a vulnerability based on exploitability and impact factors.
CWE
Common Weakness Enumeration; a categorized list of common software and hardware weakness types that can lead to exploitable vulnerabilities.
CySA+
CompTIA Cybersecurity Analyst+, an intermediate-level certification validating skills in threat detection, vulnerability management, incident response, and security reporting using behavioral analytics.
EDR
Endpoint Detection and Response; software that continuously monitors endpoint activity, detects suspicious behavior, and enables analysts to investigate and respond, such as isolating a host.
False Negative
A failure to detect and alert on activity that is actually malicious, allowing a real threat to go unnoticed.
False Positive
An alert or detection that flags activity as malicious when it is actually benign.
IOC
Indicator of Compromise; forensic artifact (file hash, IP address, domain, registry key) suggesting a system has already been breached.
IPS
Intrusion Prevention System; a network security control that sits inline with traffic and can actively block or drop packets identified as malicious.
Lateral Movement
Techniques an attacker uses to move from an initially compromised system to other systems within the same network in pursuit of further access or objectives.
Legal Hold
A formal instruction to preserve data and records relevant to anticipated or ongoing litigation or investigation, overriding normal retention/deletion schedules.
MITRE ATT&CK
A publicly available knowledge base that catalogs real-world adversary tactics and techniques, used for threat modeling, detection engineering, and gap analysis.
Order of Volatility
The standard sequence for collecting forensic evidence, prioritizing the most transient data sources (memory, cache) before more persistent ones (disk, backups).
Playbook
A documented, repeatable set of procedures that guides analysts through handling a specific category of security incident consistently.
SBOM
Software Bill of Materials; a formal inventory of all software components and dependencies in an application, used to assess supply-chain exposure.
SIEM
Security Information and Event Management; a platform that aggregates and correlates log and event data from across an environment to support detection and investigation.
SOAR
Security Orchestration, Automation, and Response; tools that automate playbook-driven remediation and coordinate actions across multiple security products.
SOC
Security Operations Center; the team and facility responsible for continuous monitoring, detection, and initial response to security events.
Threat Intelligence
Processed, contextualized information about existing or emerging threats, adversary capabilities, and infrastructure that supports proactive defensive decision-making.
TTP
Tactics, Techniques, and Procedures; the behavioral patterns describing how a specific threat actor operates, used to profile and detect adversaries.
UEBA
User and Entity Behavior Analytics; a detection approach that baselines normal behavior for users and devices and flags statistically significant deviations as potential threats.
Vulnerability Management
The continuous, cyclical process of identifying, evaluating, prioritizing, and remediating security weaknesses across an organization's assets.
Zero-Day Vulnerability
A previously unknown software flaw for which no official patch exists at the time it is discovered or exploited, leaving defenders with no vendor-provided fix.

Sources

  1. 1.CompTIA CySA+ (CS0-003) Certification Exam DetailsCompTIA (accessed Jul 18, 2026)
  2. 2.CompTIA Certification Renewal PolicyCompTIA (accessed Jul 18, 2026)
  3. 3.CompTIA CySA+ Certification OverviewCompTIA (accessed Jul 18, 2026)
  4. 4.Pearson VUE — CompTIA Exam Delivery and SchedulingPearson VUE (accessed Jul 18, 2026)

Official sources

Primary documents used to verify the exam details shown on this page.

Last verified against the CompTIA exam objectives: