The CompTIA Cybersecurity Analyst (CySA+) certification verifies that successful candidates have the knowledge and skills required to leverage intelligence and threat detection techniques, analyze and interpret data, identify and address vulnerabilities, suggest preventative measures, and effectively respond to and recover from incidents.
The CompTIA CySA+ certification is a vendor-neutral credential. The CompTIA CySA+ exam (Exam CS0-002) is an internationally targeted validation of intermediate-level security skills and knowledge. The course has a technical, “hands-on” focus on IT security analytics.
The CompTIA CySA+ exam is based on these objectives:
The CompTIA Cybersecurity Analyst (CySA+) examination is designed for IT security analysts, vulnerability analysts, or threat intelligence analysts. The exam will certify that the successful candidate has the knowledge and skills required to configure and use threat detection tools, perform data analysis, and interpret the results to identify vulnerabilities, threats, and risks to an organization with the end goal of securing and protecting applications and systems within an organization.
While there is no required prerequisite, the CompTIA CySA+ certification is intended to follow CompTIA Security+ or equivalent experience. It is recommended for CompTIA CySA+ certification candidates to have the following:
Part 1 - Threat Management
Given a scenario, apply environmental reconnaissance techniques using appropriate tools and processes:
Given a scenario, analyze the results of a network reconnaissance Point-in-time data analysis:
Given a network-based threat, implement or recommend the appropriate response and countermeasure:
Explain the purpose of practices used to secure a corporate environment:
Part 2 - Vulnerability Management
Given a scenario, implement an information security vulnerability management process:
Given a scenario, analyze the output resulting from a vulnerability scan:
Part 3 - Cyber Incident Response
Given a scenario, distinguish threat data or behavior to determine the impact of an incident:
Given a scenario, prepare a toolkit and use appropriate forensics tools during an investigation:
Explain the importance of communication during the incident response process:
Given a scenario, analyze common symptoms to select the best course of action to support incident response:
Summarize the incident recovery and post-incident response process:
Verify logging/communication to security monitoring:
Part 4 - Security Architecture and Tool Sets
Explain the relationship between frameworks, common policies, controls, and procedures:
Given a scenario, use data to recommend remediation of security issues related to identity and access management:
Given a scenario, review security architecture and make recommendations to implement compensating controls:
Given a scenario, use application security best practices while participating in the Software Development Life Cycle (SDLC):
Compare and contrast the general purpose and reasons for using various cybersecurity tools and technologies:
This course will help prepare you to take the CompTIA CySA+ exam CS0-002.
The exam voucher is included in the course fee.