CompTIA Certification

CySA+

CompTIA Cybersecurity Analyst (CS0-004 V4)

Current CS0-004 V4 track|4 domains · 61 lessons and reviews|Free Preview

Build analyst judgment across telemetry, malicious-activity analysis, vulnerability prioritization, incident response, and operational reporting.

Start a Free Lesson →

Exam Details

CySA+ V4 exam details
DetailCySA+ V4 (CS0-004)
FormatUp to 85 multiple-choice and performance-based questions
Time165 minutes
Passing score750 on a 100–900 scale
ExperienceApproximately four years of hands-on SOC analyst level 2 or vulnerability analyst experience recommended
LaunchJune 23, 2026

Source and Scope Note

Track scope checked August 29, 2026. The references were CompTIA’s public CySA+ V4 certification page and CS0-004 objectives document version 2.0. The exam launched June 23, 2026.

This note records the objectives used for the track; it does not mean CompTIA reviewed or endorsed the lessons. TheCertCoach independently created the material from public sources. Practice material is original and does not reproduce recalled or live exam items. Report a content issue.

What the CySA+ Course Includes

44Objective-aligned teaching modules
17Section reviews and domain capstones
444Original knowledge-check, review, capstone, and practice questions

The track follows the four CS0-004 domains at their published weights: Security Operations (34%), Vulnerability Management (26%), Incident Response and Management (24%), and Reporting and Communication (16%). The 150-question practice bank uses the same distribution, and shorter mixed exams preserve those proportions.

Lessons emphasize analyst decisions and evidence: telemetry and indicator analysis, SIEM and endpoint output, CVSS and EPSS context, threat hunting, attack-surface management, incident timelines and evidence handling, recovery validation, and audience-appropriate reporting. V4 topics such as AI in security operations, ZTNA and SASE, cloud-native environments, software supply-chain risk, and security automation are included where the public objectives place them.

Four lessons are free to preview—one from each domain: telemetry pipelines, scan scoping, Cyber Kill Chain analysis, and findings and action plans.

Course Outline

Domain 1 — Security Operations (34%)

Section A — Architecture and Telemetry Foundations

  1. 1 SOC Telemetry Pipeline: Ingestion, Time, Integrity, and Retention Free Free Preview
  2. 2 Operating Systems, Endpoints, and Mobile Telemetry Full Access
  3. 3 Cloud-Native, Virtualized, Containerized, and API Environments Full Access
  4. 4 Hybrid Network Architecture: ZTNA and SASE Full Access
  5. 5 Identity, Privileged Access, Secrets, Encryption, and Data Protection Full Access
  6. 6 OT, ICS, and SCADA Security Operations Full Access
  7. Section A Review Full Access

Section B — Indicator Analysis

  1. 7 Network and Host Indicators Full Access
  2. 8 Application, Cloud, and Configuration Indicators Full Access
  3. 9 Identity, Email, and Social-Engineering Indicators Full Access
  4. Section B Review Full Access

Section C — Analyst Tools and Evidence

  1. 10 Packet and Network Analysis Tools Full Access
  2. 11 SIEM, UEBA, Log Analysis, and Event Formats Full Access
  3. 12 Endpoint, File, and Sandbox Analysis Full Access
  4. 13 Threat-Intelligence, Reputation, and Email Analysis Tools Full Access
  5. 14 Analyst Automation: Decoding, Scripting, Regex, and Suspicious Commands Full Access
  6. Section C Review Full Access

Section D — Threat Intelligence, Improvement, and AI

  1. 15 Threat-Intelligence Quality, Sources, and Indicators Full Access
  2. 16 Threat Hunting, Mapping, Modeling, and Deception Full Access
  3. 17 Improving SOC Operations with Runbooks, Enrichment, SOAR, IaC, and Integrations Full Access
  4. 18 AI in Security Operations: Use Cases, Validation, Risks, and Governance Full Access
  5. Section D Review Full Access

Domain 1 Review

  1. Capstone: The Meridian Components Investigation Full Access
Domain 2 — Vulnerability Management (26%)

Section A — Plan and Perform Vulnerability Scanning

  1. 19 Build Scan Scope from Asset Inventory Free Free Preview
  2. 20 Choose a Safe and Appropriate Scan Method Full Access
  3. 21 Baseline and Compliance Scanning Full Access
  4. Section A Review: Scan Strategy and Execution Full Access

Section B — Analyze Assessment-Tool Output

  1. 22 Read Network-Mapping and Vulnerability-Scanner Output Full Access
  2. 23 Web Application Assessment Tools Full Access
  3. 24 Cloud, Container, and IaC Assessment Tools Full Access
  4. 25 Multipurpose Reconnaissance and Breach-Attack Simulation Tools Full Access
  5. Section B Review: Assessment Evidence Full Access

Section C — Prioritize and Mitigate Vulnerabilities

  1. 26 Validate Findings and Classification Errors Full Access
  2. 27 Prioritize Beyond Severity with CVSS, EPSS, Threat, Asset, and Business Context Full Access
  3. 28 Choose, Document, and Validate Mitigations Full Access
  4. Section C Review: Prioritization and Mitigation Full Access

Section D — Controls, Risk, and Program Governance

  1. 29 Control Functions, Risk Treatment, Governance, and SLOs Full Access
  2. 30 Application-Security Assessment Programs: SAST, DAST, and SAMM Full Access
  3. 31 Third-Party and Software Supply-Chain Risk: SCA and SBOM Full Access
  4. Section D Review: Controls and Governance Full Access

Domain 2 Review

  1. Capstone: Restore Confidence in the Meridian Booking Platform Full Access
Domain 3 — Incident Response and Management (24%)

Section A — Attack Methodology Frameworks

  1. 32 Cyber Kill Chain Analysis Free Free Preview
  2. 33 Diamond Model Intrusion Analysis Full Access
  3. 34 MITRE ATT&CK and Complementary Mapping Full Access
  4. Section A Review: Attack Methodology Frameworks Full Access

Section B — Incident Response Process

  1. 35 Preparation, Detection, and Analysis Full Access
  2. 36 Containment, Eradication, and Recovery Full Access
  3. 37 Post-Incident Learning and Lifecycle Coordination Full Access
  4. Section B Review: Incident Response Process Full Access

Section C — Incident Response Techniques

  1. 38 Plans, Playbooks, Telemetry, and Triage Full Access
  2. 39 Evidence Gathering and Preservation Full Access
  3. 40 Isolation, Remediation, Restoration, and Root Cause Full Access
  4. Section C Review: Incident Response Techniques Full Access

Domain 3 Review

  1. Domain 3 Capstone: Coordinated SaaS Account Intrusion Full Access
Domain 4 — Reporting and Communication (16%)

Section A — Vulnerability Management Reporting

  1. 41 Findings, Scorecards, and Action Plans Free Free Preview
  2. 42 Remediation Barriers, Stakeholders, and Metrics Full Access
  3. Section A Review: Vulnerability Management Reporting Full Access

Section B — Security Operations and Incident Communication

  1. 43 Incident Declaration, Escalation, and Stakeholder Communication Full Access
  2. 44 Post-Incident Reports, Handovers, Intelligence, and Metrics Full Access
  3. Section B Review: Security Operations and Incident Communication Full Access

Domain 4 Review

  1. Domain 4 Capstone: Reporting a Critical Third-Party Vulnerability and Incident Full Access
Open the 150-Question Practice Bank →

Where CySA+ Fits

Security+ establishes broad security foundations. CySA+ goes deeper into analyst work: interpreting evidence, prioritizing vulnerabilities, coordinating incident response, and communicating operational decisions. CompTIA recommends relevant hands-on experience but does not require Security+ as a prerequisite.

It aligns most closely with work performed by SOC analysts, vulnerability analysts, incident responders, threat hunters, and other practitioners who turn security evidence into prioritized action. A certification can support a career move, but it does not replace relevant experience or guarantee a role.

Compare Security+ and CySA+ →
Compare all certification tracks →