image

This course prepares learners for the CompTIA CySA+ CS0-004 (V4) exam. The V4 update applies behavioral analytics to combat modern threats through continuous monitoring, incident response, and vulnerability management. It introduces dedicated coverage of artificial intelligence (AI) use cases and risks, modern security architectures used in today’s Security Operations Centers (SOCs), and advanced vulnerability management practices such as SBOM and EPSS-based prioritization.

The CySA+ certification is also DoD 8570/8140 approved, making this course an excellent choice for military, civilian, and contractor personnel who require compliance with Department of Defense cybersecurity workforce standards.

System and Network Architecture Concepts for Secure Operations

Secure operations depend on a foundation of architectural controls that provide visibility, enforce trust, and protect data. Key concepts include:

  • Logging and monitoring: Centralized collection of system, application, and network logs to support detection, investigation, and audit requirements.
  • Identity and access management: Authentication, authorization, and accounting (AAA) mechanisms, including multifactor authentication (MFA), single sign-on (SSO), and least-privilege access.
  • Encryption: Protection of data in transit and at rest using strong cryptographic standards and sound key management practices.
  • Modern frameworks:
    • Zero Trust Network Access (ZTNA): Continuously verifies identity and context before granting access, replacing implicit network trust.
    • Secure Access Service Edge (SASE): Converges networking and security services in the cloud to protect distributed users and resources.
    • Cloud-native architecture: Leverages containers, microservices, and orchestration with security integrated into deployment pipelines.

Detecting and Analyzing Indicators of Malicious Activity

Analysts must identify signs of compromise across multiple domains:

  • Network: Anomalous traffic patterns, unexpected outbound connections, and command-and-control indicators.
  • Endpoints: Suspicious processes, unauthorized software, and abnormal file or registry changes.
  • Cloud: Misconfigurations, unusual API calls, and unauthorized resource provisioning.
  • Identity systems: Impossible travel, privilege escalation, and abnormal authentication behavior.

Tools and Methods for Determining Malicious Activity

Industry-standard tools support detection and investigation:

  • SIEM: Aggregates and correlates log data to surface security events and alerts.
  • EDR/XDR: Provides endpoint and extended detection and response across multiple telemetry sources.
  • Packet analyzers: Enable deep inspection of network traffic for forensic and detection purposes.
  • Threat intelligence platforms: Deliver context on adversary tactics, techniques, and indicators of compromise.

Applying Threat Intelligence and Threat Hunting

Proactive defense combines intelligence and investigation:

  • Consume strategic, operational, and tactical threat intelligence to inform defenses.
  • Develop and test hypotheses about adversary behavior using frameworks such as MITRE ATT&CK.
  • Hunt for threats that evade automated detection by analyzing patterns and anomalies.

Running a Vulnerability Management Program

An effective program follows a repeatable, risk-based cycle:

  • Scanning: Regular discovery of assets and identification of vulnerabilities.
  • Analysis: Validation of findings to eliminate false positives.
  • Prioritization: Ranking vulnerabilities using CVSS for severity and EPSS for exploitation likelihood.
  • Risk-based remediation: Addressing vulnerabilities according to business impact and threat context.

Executing the Incident Response Lifecycle

Structured incident response reduces impact and supports recovery:

  • Detection: Identifying and validating security incidents.
  • Containment: Limiting the spread and impact of the incident.
  • Eradication: Removing the threat and its artifacts from the environment.
  • Recovery: Restoring systems and services to normal operation.
  • Post-incident activities: Conducting lessons-learned reviews and improving controls.

AI in Security Operations

Artificial intelligence introduces both opportunities and risks:

  • Use cases: Alert triage, anomaly detection, automation of repetitive tasks, and analyst assistance.
  • Security risks: Adversarial attacks, data poisoning, model bias, and misuse of generative tools by attackers.
  • Governance considerations: Oversight, transparency, data protection, and accountability for AI-driven decisions.

Vulnerability and Incident Response Reporting

Clear reporting enables informed stakeholder decisions:

  • Communicate findings in business-relevant terms with clear risk context.
  • Provide actionable recommendations and prioritized remediation guidance.
  • Tailor detail and language to technical and executive audiences.
  • Support decision-making with metrics, timelines, and impact assessments.
Virtual Instructor-Led Training 5 days / 40 hours

Upcoming Schedules

Date Time Enroll
Aug 17 - Aug 21, 2026 9:00 AM - 5:00 PM America/New_York Add To Cart
Sep 14 - Sep 18, 2026 9:00 AM - 5:00 PM America/New_York Add To Cart
Oct 12 - Oct 16, 2026 9:00 AM - 5:00 PM America/New_York Add To Cart
Nov 16 - Nov 20, 2026 9:00 AM - 5:00 PM America/New_York Add To Cart
Dec 07 - Dec 11, 2026 9:00 AM - 5:00 PM America/New_York Add To Cart
Jan 11 - Jan 15, 2027 9:00 AM - 5:00 PM America/New_York Add To Cart

Who should attend CompTIA Cybersecurity Analyst (CySA+) Course

This course is ideal for IT cybersecurity professionals with three to four years of hands-on information security or related experience, including:

  • Security analysts and SOC (Security Operations Center) analysts
  • Vulnerability analysts and threat intelligence analysts
  • Security engineers and security operations staff
  • Incident responders and incident response analysts
  • Application security analysts and compliance/risk analysts

Prerequisites for CompTIA Cybersecurity Analyst (CySA+) Course

Approximately three to four years of hands-on information security or related experience. CompTIA Security+ (or equivalent knowledge and experience) is recommended prior to attending.

CompTIA Cybersecurity Analyst (CySA+) Course Outline

  • Logging concepts: ingestion, configuration, integrity and security, time synchronization, and retention
  • Operating system concepts, hardening, file structures, and critical processes
  • Infrastructure concepts: cloud-native, virtualization, containerization, and APIs
  • Network architecture: Zero Trust Network Access (ZTNA), SASE, and hybrid cloud
  • Identity and access management: PAM, authentication/authorization methods, and secrets management
  • Encryption, data protection, and OT/ICS/SCADA fundamentals
  • Security control types (physical, technical, administrative) and control functions
  • Network-based indicators: rogue devices, enumeration, and unexpected ports/traffic
  • Host-based indicators: resource spikes, unauthorized software, LOLBins, and file changes
  • Application- and cloud-based anomalies
  • Identity-based indicators: impossible travel and unauthorized access
  • Social engineering and Business Email Compromise (BEC)
  • Packet capture and analysis (Wireshark, tcpdump) and IDS/IPS engines (Snort, Suricata, Zeek)
  • SIEM, EDR/XDR, and threat intelligence platforms (TIPs)
  • File and reputation analysis; common log and file formats (JSON, XML, YAML, EVTX)
  • Scripting for analysis with Python, PowerShell, and shell
  • Threat actors, motivations, and TTPs; MITRE ATT&CK and the pyramid of pain
  • Indicators of compromise: collection, analysis, and application (atomic vs. behavioral)
  • Threat modeling (STRIDE), threat mapping, and cyber deception
  • Standardized playbooks and runbooks; SOAR and automation/orchestration
  • Data enrichment, alert and rule tuning, and dashboards
  • Tool integration via APIs, webhooks, and plug-ins
  • AI use cases in the SOC: log analysis, event correlation, documentation, investigations, and automation
  • AI security risks: hallucinations, data exposure, model poisoning, and malicious prompts (prompt injection)
  • AI governance and oversight: usage policies and legal/regulatory considerations
  • Asset discovery and inventory; scan planning for scope, sensitivity, segmentation, and regulatory needs
  • Internal vs. external, agent vs. agentless, credentialed vs. non-credentialed, active vs. passive scanning
  • Baseline and compliance scanning (PCI DSS, CIS, ISO 27000)
  • Interpreting scanner output; validating, consolidating, and deduplicating findings
  • Risk scoring with CVSS plus context; prioritization using the Exploit Prediction Scoring System (EPSS)
  • Handling false positives and tracking exceptions
  • Software supply chain security and Software Bill of Materials (SBOM)
  • Controls to mitigate: patching, configuration changes, and compensating controls
  • Change windows, rollback planning, retesting, and remediation validation
  • Risk-based remediation planning and inhibitors to remediation
  • Cyber kill chain, MITRE ATT&CK, and the Diamond Model of Intrusion Analysis
  • Testing guides and methodologies (OSSTMM, OWASP) for context
  • Lifecycle: detection, analysis, containment, eradication, and recovery
  • Evidence acquisition and digital forensics fundamentals
  • Root-cause analysis
  • Incident response plans, tooling, and playbooks
  • Tabletop exercises and training; business continuity and disaster recovery alignment
  • Post-incident review and lessons learned
  • Compliance reporting, action plans, and inhibitors to remediation
  • Metrics and KPIs; communicating risk to stakeholders
  • Incident declaration, escalation, and stakeholder identification
  • Incident reporting, root-cause summaries, and lessons-learned communication

Resources

FAQs on CompTIA Cybersecurity Analyst (CySA+)

It targets IT security professionals with 3-4 years of hands-on experience, including SOC analysts, threat intelligence analysts, security engineers, incident responders, and application security/compliance analysts.

Approximately three to four years of hands-on information security experience is required. CompTIA Security+ certification or equivalent knowledge is recommended but not mandatory.

The course covers Zero Trust Network Access (ZTNA), Secure Access Service Edge (SASE), cloud-native architecture, virtualization, containerization, and hybrid cloud models as part of secure system and network design.

The course covers system/network architecture concepts, identifying indicators of malicious activity, logging and monitoring, identity and access management, encryption, OT/ICS/SCADA security, and analysis of network, host, application, and identity-based threat indicators.

The course builds skills in secure system and network architecture, threat detection, and incident analysis, preparing professionals to identify, monitor, and respond to cybersecurity threats using modern frameworks and tools.