Certification guide
CS0-003CompTIA CySA+: the honest guide
CySA+ is the certification for the analyst seat. It assumes you can already read a scan result, a SIEM alert and a packet capture, and it spends most of its questions asking what that output means and what you do next. That is a different test from the one below it, and the difference is the whole point of taking it.
The exam is a maximum of 85 questions in 165 minutes, mixing multiple choice with performance-based items, and the pass mark is 750 on a scale of 100 to 900. Security operations and vulnerability management are 63 percent of it between them, so the exam rewards time spent in front of real tool output far more than time spent reading about it.
Who CySA+ is for
A good fit if
- You work in a SOC, or want to, and need proof you can triage an alert rather than define one.
- You hold Security+ and want the next step toward detection, vulnerability management and incident response.
- You need CySA+ for a DoD 8140 analyst work role.
- You already do vulnerability management or incident work informally and need the credential to match.
Probably not, if
- You have never opened a SIEM, run a scanner or read a packet capture. CySA+ hands you that output cold and marks you on reading it. Get hands-on with logs and scan results first, even in a home lab.
- You want an entry-level credential. This is an intermediate exam that assumes security fundamentals. Security+ or ISC2 CC is the better first step.
- You want offensive, hands-on-keyboard hacking. That is PenTest+. CySA+ is a defensive, analysis exam.
Is CySA+ worth it?
For a working or aspiring security analyst, yes. CySA+ is named in SOC and analyst job postings, it is approved for several DoD 8140 work roles, and the skills it forces you to build, reading output and deciding what matters, are the daily job. Check the current DoD 8140 tables for the exact role you are targeting, because the mappings get revised.
For someone already senior in detection and response with years behind them, it is worth having rather than worth studying for. You will pass it without much new learning, and it ticks a contract or promotion box. If nothing is forcing it, the money and time go further on a higher credential.
For someone with no security exposure hoping it produces a first job on its own, no. CySA+ is a second or third certification. It assumes the fundamentals Security+ covers and the comfort with tools that a first support or security role builds. Skipping to it tends to raise a question in an interview rather than answer one.
What the exam actually asks you to do
Multiple choice, multiple response, and performance-based questions. The performance-based items drop you into a simulated console, network diagram, or configuration screen and score what you actually do.
Item formats
- Multiple choice
- Multiple response
- Performance-based
The highlighted formats are the ones you cannot answer from memory alone. CompTIA, CySA+ exam details ↗
Domain breakdown and official weightings
From the official CompTIA exam objectives. Security Operations is the heaviest domain at 33 percent, followed by Vulnerability Management at 30 percent.
- Security Operations33%
- Vulnerability Management30%
- Incident Response and Management20%
- Reporting and Communication17%
Where to focus: Security operations and vulnerability management are 63 percent of the exam between them. Time spent reading real scanner output pays back more than any other activity here.
Study plans by experience level
Holding Security+, comfortable reading logs
6 to 8 weeksat 8 to 10 hours
- 1Week 1: read the CS0-003 objectives end to end and mark every line you could define but not yet act on. That marked list is your syllabus, not the whole document.
- 2Weeks 2 to 4: security operations at 33 percent, the largest domain. Work from real artifacts. Read SIEM alerts, correlate log sources, and practise telling a true positive from noise rather than reciting what a SIEM is.
- 3Weeks 5 to 6: vulnerability management at 30 percent. This is prioritisation, not scanning. Read scanner output, map findings to CVSS and asset context, and decide what you would remediate first and why.
- 4Week 7: incident response at 20 percent and reporting and communication at 17 percent. The reporting domain is the easiest marks on the exam and the one technical candidates skip.
- 5Week 8: performance-based practice and timed full mocks. Book the exam when your mock scores sit consistently above 85 percent.
Working in IT or security, new to analyst tooling
10 to 12 weeksat 6 to 8 hours
- 1Weeks 1 to 2: stand up a lab you can generate output in. A free SIEM, a vulnerability scanner and Wireshark on a couple of virtual machines is enough to make everything after this concrete.
- 2Weeks 3 to 6: security operations. Log types and sources, common attack patterns as they look in telemetry, and threat intelligence. Read output every session rather than reading about output.
- 3Weeks 7 to 9: vulnerability management. Scan types, CVSS scoring, and the reasons a valid finding still gets deprioritised in a real environment.
- 4Weeks 10 to 11: incident response and the reporting domain. Practise writing a short, plain incident summary, because the exam tests communication as much as detection.
- 5Week 12: performance-based practice and full timed mocks under time pressure.
Already doing SOC or vulnerability work
3 to 4 weeksat 5 hours
- 1Read the objectives and mark only what your daily role does not cover. For most working analysts that is the formal framework names and the reporting domain.
- 2Take a full timed mock at the end of week one. It names the gap between doing the work and answering CompTIA's questions about it faster than reading will.
- 3Study the marked items and nothing else. Re-reading tools you use every shift feels productive and moves your score by very little.
- 4Spend the last week on performance-based practice and the exact terms CompTIA uses for things you do by habit. The exam marks their vocabulary, not yours.
Common mistakes
- Studying it like Security+
- Security+ asks what a control is. CySA+ hands you a scan result, a SIEM alert or a capture and asks what it means. Memorising definitions gets you a passing Security+ score and a failing CySA+ one. Practise on real output from the first week rather than the last.
- Treating vulnerability management as running scans
- The domain is 30 percent of the exam and almost none of it is about launching a scan. It is prioritisation: which finding matters given the asset, the exposure and the CVSS vector, and which valid finding you leave for later. The exam gives you output and asks you to rank it.
- Writing off reporting and communication
- It is 17 percent of the exam, it is not technical, and technical candidates skip it for exactly that reason. Writing a clear incident summary and knowing which metric a given stakeholder needs are testable skills, and they are the cheapest marks on the paper.
- Meeting the performance-based questions in the exam
- They take longer than a multiple choice item and they are a different skill, usually built around interpreting output or sequencing a response. Candidates who leave them until the last week see the format for the first time with the clock running.
- Booking the exam to create pressure
- Paying $425 in advance to motivate yourself works until the date arrives and your mocks are still short. Book when your scores say you are ready. The deadline you need is a study schedule, not a receipt.
- Ignoring the score report after a failure
- CompTIA breaks a failed result down by domain. It is the most specific study guidance you will get, and rebooking without reading it is how a domain-shaped gap costs you a second $425.
What comes after passing
CySA+ is valid for three years. Renewal is 60 continuing education units across the cycle plus CompTIA's continuing education fee, or re-sitting the current version of the exam. If you go on to a higher security certification during the cycle, that alone can cover the CEU requirement, so the renewal costs nothing extra.
The next steps split by direction. PenTest+ if you want to move toward offensive work, SecurityX (the renamed CASP+) if you are heading for a senior technical or security engineering role, and a vendor SOC or SIEM certification if your shop runs a specific platform. CISSP is the management-track option, though it wants five years of experience before it will certify you.
The DoD 8140 approval is worth acting on if you are near government or contractor work. CySA+ is approved for several 8140 work roles, so once you hold it, search those role titles specifically. Confirm the mapping on the current 8140 tables first, because CompTIA and the DoD both revise them.
Where people go next
Costs across the full renewal cycle are on the CySA+ cost page.
Frequently asked questions
Is CySA+ harder than Security+?
Yes, in a specific way. Security+ asks what a control is. CySA+ hands you output, a scan result, a SIEM alert or a packet capture, and asks what it means and what you do next. If you can read those three without a reference sheet, you are close.
What does CS0-003 cover?
Four domains: security operations at 33 percent, vulnerability management at 30 percent, incident response and management at 20 percent, and reporting and communication at 17 percent. The first two are 63 percent of the exam between them, so most of your study time belongs there.
How long does CySA+ take to study for?
Six to eight weeks at 8 to 10 hours a week if you already hold Security+ and read logs comfortably. Ten to twelve weeks if analyst tooling is new to you. Three to four weeks if you already do the work and mainly need CompTIA's vocabulary for it.
Do I need Security+ before CySA+?
CompTIA recommends Security+ and around four years of hands-on experience, but neither is enforced. The real gate is comfort with logs, scanners and captures, not a certificate. If that output is unfamiliar, start there rather than with an exam booking.
What score do I need to pass CySA+?
750 on a scale of 100 to 900, across a maximum of 85 questions in 165 minutes. The exam mixes multiple choice with performance-based items, and the performance-based ones carry more weight, so the raw question count and the scaled score do not map cleanly onto each other.
Does CySA+ count for DoD 8140?
It is approved for several DoD 8140 work roles, which is a large part of why it holds its value in government and contractor hiring. Check the current 8140 tables for the specific role you are targeting, because the mappings are revised.
Keep reading
- CySA+ practice questions
Free sample questions with the full explanation on every answer.
- Free CySA+ practice test
Ten real questions, playable now. No account, no card.
- CySA+ exam objectives
The full official blueprint, with practice pages on covered objectives.
- CySA+ passing score
The exact cut score, what kind of number it is, and the retake terms.
- How hard is CySA+?
An honest difficulty read from the format, the clock and the weights.
- What CySA+ costs
The voucher price, the retake, and what renewal costs across the cycle.
Cheat sheets
Printable reference tables, free.
Compared with
Side by side on cost, difficulty, and which one to take first.
Practise CySA+ for free while you decide
Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.
Start free CySA+ questions