Free study resourceIndependently authoredAnalyst workflow focused

CompTIA CySA+ study hub

Move from security fundamentals into analyst judgment: interpret telemetry, prioritize exploitable exposure, manage incidents, and communicate evidence so another person can make the next decision.

Current exam facts on this track are rendered from Zeph Tech's reviewed certification registry. Transition dates for older exam versions are intentionally omitted unless the certification owner is the source.

Current exam record

Keep volatile exam facts in one reviewed source.

Exam code, version, time, scoring, domain weighting, and review date are rendered from the certification registry rather than copied throughout this page.

Active

Last verified: 2026-09-25

Next review: 2026-10-25

Official certification page · Official exam objectives

Published domain weighting

Domain map

Study the analyst workflow, not a list of product names.

The four current domains form a continuous operating loop: observe, prioritize, respond, and communicate.

Security Operations

Architecture context, logs and telemetry, malicious-activity indicators, threat intelligence and hunting, detection tooling, process improvement, automation, and safe use of AI in security operations.

Practice by asking: what evidence is trustworthy, what normal looks like, and what additional observation would confirm or disprove the hypothesis?

Vulnerability Management

Assessment methods, scanner output, true and false positives, exploitability, threat intelligence, asset context, severity scoring, remediation, compensating controls, exceptions, and validation.

Practice by asking: which weakness creates the most credible loss path now, and what evidence proves the fix changed exposure?

Incident Response and Management

Attack frameworks, triage, containment, eradication, recovery, evidence handling, forensic technique, root-cause analysis, lessons learned, and coordinated decision-making.

Practice by asking: what must be preserved, what can be safely contained, who owns the decision, and what proves recovery?

Reporting and Communication

Vulnerability and incident reporting, metrics, escalation, stakeholder communication, risk statements, remediation ownership, and translating technical findings for different audiences.

Practice by asking: what does this audience need to decide, who owns the next action, and what uncertainty must be stated explicitly?

Analyst loop

Use the same evidence discipline across all four domains.

CySA+ scenarios become easier when every tool output is treated as evidence that still requires context, validation, and communication.

1. Establish scope and time

Identify the affected asset, user, service, trust boundary, data source, time window, and business consequence. Normalize timestamps before correlating systems.

2. Build and test a hypothesis

Use logs, endpoint evidence, network telemetry, cloud audit data, threat intelligence, vulnerability records, and identity context to narrow possibilities instead of treating one alert as proof.

3. Prioritize by credible risk

Combine severity with exploitation evidence, reachability, asset value, existing controls, remediation availability, and operational consequence. A high score without a viable attack path can rank below an actively exploited exposed weakness.

4. Act, verify, communicate

Contain or remediate using an owned decision, verify that the control changed the evidence, preserve the record, and report the result in language appropriate to the audience.

Original practice

CySA+ analyst diagnostic exam.

Twenty independently authored questions cover all four current domains. They are study scenarios based on public objectives and technical standards, not recalled or copied live exam items.

Loading the interactive practice exam. If it does not load, ensure JavaScript is enabled.

Six-week example

A practical CySA+ study sequence.

Weight study time toward the published blueprint, but let repeated mistakes determine where the next block goes.

Week 1: telemetry and architecture

Review logging pipelines, time synchronization, endpoint/network/cloud/identity telemetry, hardening, zero-trust concepts, and how architecture changes the meaning of an indicator.

Week 2: malicious activity and hunting

Practice reading process, authentication, DNS, HTTP, firewall, endpoint, and cloud events. Map behavior to hypotheses and ATT&CK-style tactics without assuming every anomaly is malicious.

Week 3: vulnerability decisions

Work through scan methods, validation, CVSS, exploitation evidence, asset value, internet exposure, exceptions, compensating controls, patching, and proof of remediation.

Week 4: incident response

Run table-top scenarios from detection through containment, evidence preservation, eradication, recovery, root cause, and corrective action. Record which decisions need business or legal ownership.

Week 5: reporting and metrics

Rewrite the same finding for an analyst, system owner, executive, and auditor. Practice useful metrics such as aging, recurrence, detection/response time, coverage, exceptions, and verified closure.

Week 6: mixed retrieval

Take the diagnostic under a time limit, review every incorrect or guessed response, revisit weak-domain resources, and finish with the certification owner's current objectives as the checklist.

Independent study resource

CompTIA remains the authority for the exam.

Zeph Tech's practice material is independently authored for learning and is not copied from, recalled from, or represented as live exam content. When a Zeph Tech fact conflicts with CompTIA's current certification page or objectives, the owner source controls and the registry must be corrected.

CySA+ analyst reasoning: connect evidence, confidence, and action

CySA+ rewards analysts who can move from incomplete evidence to a defensible next action. Start by separating observation from conclusion. A suspicious process, failed login burst, unusual DNS request, cloud audit event, or vulnerability finding is evidence; “account compromise” or “malware infection” is an interpretation that should be supported by additional signals. That distinction helps avoid both premature escalation and missed incidents.

When reading logs, establish the timeline first. Normalize timestamps, identify the affected identity or asset, and look for events immediately before and after the alert. Authentication success after repeated failures, a new process after a downloaded file, a privilege change before data access, or outbound traffic after persistence activity can transform isolated events into a coherent attack narrative.

Vulnerability-management questions require risk context rather than CVSS memorization alone. Consider exploitability, exposure, asset criticality, compensating controls, active exploitation, business ownership, patch availability, and the consequence of remediation. A lower-scored issue on an internet-facing critical service may deserve faster action than a higher-scored issue on an isolated laboratory system.

Detection engineering and triage

For alert-tuning scenarios, distinguish false positives from benign positives. A false positive means the detection logic incorrectly identified the event; a benign positive means the rule correctly detected the behavior but the behavior is authorized or expected. The tuning response may differ: change logic for false positives, while approved exceptions, enrichment, or context may be better for recurring benign positives.

Know what each evidence source can prove. Endpoint telemetry is strong for process and file activity; network telemetry reveals flows and protocol behavior; identity logs expose authentication and privilege events; cloud control-plane logs show administrative actions; vulnerability scanners identify known weaknesses; threat intelligence supplies external context. Good analysis correlates sources instead of treating one feed as complete truth.

Reporting that drives remediation

Technical findings should translate into decisions. For an analyst audience, preserve indicators, timestamps, affected systems, queries, and confidence. For management, explain business impact, scope, containment status, remediation ownership, and residual risk. CySA+ scenarios often test whether the communication matches the stakeholder and whether recommendations are specific enough to act on.

Review missed questions by writing the evidence you had, the assumption you made, the missing evidence that would increase confidence, and the action justified at that confidence level. That exercise mirrors real analyst work and makes incident response, threat hunting, vulnerability prioritization, and reporting concepts reinforce one another instead of remaining separate exam domains.