Exam objectivesCS0-003

CompTIA CySA+ exam objectives

The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.

Titles and weightings from the official objectives. CompTIA exam page

Security Operations

33% of exam
  • 1.1 1.1 Explain the importance of system and network architecture concepts in security operations.

  • 1.2 1.2 Given a scenario, analyze indicators of potentially malicious activity.

  • 1.3 1.3 Given a scenario, use appropriate tools or techniques to determine malicious activity.

  • 1.4 1.4 Compare and contrast threat-intelligence and threat-hunting concepts.

  • 1.5 1.5 Explain the importance of efficiency and process improvement in security operations.

Vulnerability Management

30% of exam
  • 2.1 2.1 Given a scenario, implement vulnerability scanning methods and concepts.

  • 2.2 2.2 Given a scenario, analyze output from vulnerability assessment tools.

  • 2.3 2.3 Given a scenario, analyze data to prioritize vulnerabilities.

  • 2.4 2.4 Given a scenario, recommend controls to mitigate attacks and software vulnerabilities.

  • 2.5 2.5 Explain concepts related to vulnerability response, handling, and management.

Incident Response and Management

20% of exam
  • 3.1 3.1 Explain concepts related to attack methodology frameworks.

  • 3.2 3.2 Given a scenario, perform incident response activities.

  • 3.3 3.3 Explain the preparation and post-incident activity phases of the incident management life cycle.

Reporting and Communication

17% of exam
  • 4.1 4.1 Explain the importance of vulnerability management reporting and communication.

  • 4.2 4.2 Explain the importance of incident response reporting and communication.

Keep reading

Every guide and cost breakdown, by vendor