CompTIA CySA+ exam objectives
The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.
Titles and weightings from the official objectives. CompTIA exam page ↗
Security Operations
33% of exam1.1 1.1 Explain the importance of system and network architecture concepts in security operations.
1.2 1.2 Given a scenario, analyze indicators of potentially malicious activity.
1.3 1.3 Given a scenario, use appropriate tools or techniques to determine malicious activity.
1.4 1.4 Compare and contrast threat-intelligence and threat-hunting concepts.
1.5 1.5 Explain the importance of efficiency and process improvement in security operations.
Vulnerability Management
30% of exam2.1 2.1 Given a scenario, implement vulnerability scanning methods and concepts.
2.2 2.2 Given a scenario, analyze output from vulnerability assessment tools.
2.3 2.3 Given a scenario, analyze data to prioritize vulnerabilities.
2.4 2.4 Given a scenario, recommend controls to mitigate attacks and software vulnerabilities.
2.5 2.5 Explain concepts related to vulnerability response, handling, and management.
Incident Response and Management
20% of exam3.1 3.1 Explain concepts related to attack methodology frameworks.
3.2 3.2 Given a scenario, perform incident response activities.
3.3 3.3 Explain the preparation and post-incident activity phases of the incident management life cycle.
Reporting and Communication
17% of exam4.1 4.1 Explain the importance of vulnerability management reporting and communication.
4.2 4.2 Explain the importance of incident response reporting and communication.
Keep reading
CySA+ practice questions
Free sample questions with the full explanation on every answer.
CySA+ passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is CySA+?
An honest difficulty read from the format, the clock and the weights.