Triage BoardGet the app

Study guide · CS0-004

CySA+ study guide: the CS0-004 objectives, explained

This CySA+ study guide walks the CS0-004 exam objectives in order: four domains, fifteen objectives, a guide and drill for each, and separate pages for the look-alike concepts that cost points. Weights and objective titles come from the CS0-004 exam objectives, version 2.0, checked October 2026.

  • Domains 4
  • Areas 15
  • Concepts 15

The blueprint: how the exam is weighted

Security Operations carries just over a third of CS0-004. Against CS0-003, Incident Response gained four points and Vulnerability Management lost four, the largest moves between versions.

  • Security Operations34%
  • Vulnerability Management26%
  • Incident Response and Management24%
  • Reporting and Communication16%

Domain weights from the CompTIA CySA+ CS0-004 exam objectives, version 2.0 (checked October 2026).

Security Operations: six objectives, the widest net

Domain 1 is 34% of the exam and the only domain with six objectives. It checks that you can look at a host, a network segment or an identity log and say what is wrong.

  • Architecture and logging (1.1): log ingestion, time sync and retention, zero trust network access (ZTNA), identity and secrets management, OT and ICS.
  • Indicators of malicious activity (1.2): network, host, cloud and identity signs, from living-off-the-land binaries (LOLBins) to impossible travel and business email compromise.
  • Security analysis tools (1.3): packet capture, security information and event management (SIEM), endpoint detection and response (EDR), sandboxes, YARA and the file formats tools emit.
  • Threat intelligence and hunting (1.4): tactics, techniques and procedures (TTPs), confidence in intel, STRIDE threat modeling, cyber deception.
  • Automation and process improvement (1.5): playbooks, SOAR, alert tuning, APIs and webhooks.
  • AI in security operations (1.6): new in CS0-004; hallucinations, data exposure, model poisoning, malicious prompts and AI usage policy.

What trips people here is tool-name recognition. A stem that describes a symptom wants the meaning of the symptom, and the tool sitting in the options is often the distractor. Three concept pages settle the classic mix-ups: DNS tunneling vs DGA vs fast flux, SIEM vs SOAR vs EDR and the Pyramid of Pain for judging which indicators are worth chasing.

Tip: learn indicators before tools. Once you can say what a beacon or a rogue process looks like, a tool question shrinks to which tool would show it.

Vulnerability Management: from scan to fix order

Domain 2 is 26% of CS0-004, down from 30% on CS0-003, and it runs like a pipeline: plan the scan, read the output, rank the findings, choose the control.

  • Vulnerability scanning methods (2.1): asset inventory, credentialed and agent-based scans, passive and active discovery, baselines such as CIS Benchmarks and PCI DSS.
  • Vulnerability assessment tools (2.2): Nmap, Nessus, OpenVAS, Nuclei, Burp Suite, cloud scanners such as Prowler and Trivy, breach-and-attack simulation.
  • Prioritizing vulnerabilities (2.3): CVSS metrics, EPSS, exploitability, asset value, compensating controls and validating the fix.
  • Controls and risk management (2.4): control types and functions, risk appetite, the four risk responses, SAST and DAST, software composition analysis (SCA) and the SBOM.

The trap is ranking by the Common Vulnerability Scoring System (CVSS) base score alone. CS0-004 names the Exploit Prediction Scoring System (EPSS) from FIRST, and a ticket that shows both wants severity weighed against the likelihood of exploitation, then against the asset. CVSS itself changed too: CVSS v4.0 replaced v3.1's Temporal metrics with Threat metrics. The pairs to separate are CVSS vs EPSS, CVSS v4.0 vs v3.1, credentialed vs non-credentialed scans, false positive vs false negative, compensating controls, SAST vs DAST vs SCA and the four risk responses.

Tip: read scanner output field by field: host, port, plugin or template, severity. A tool ticket usually turns on one of those fields.

Incident Response and Management: order matters

Domain 3 is 24% of CS0-004, up four points, spread over three objectives.

  • Attack frameworks (3.1): the Cyber Kill Chain, the Diamond Model of Intrusion Analysis and MITRE ATT&CK.
  • Incident response process (3.2): seven steps, from preparation, detection and analysis through containment, eradication and recovery to post-incident work.
  • Incident response techniques (3.3): triage, timelines, evidence and legal hold, isolation, escalation, root cause analysis.

The step list is the first trap. CompTIA's seven steps are the ones the exam marks. NIST's older four-phase cycle from NIST SP 800-61r2 was superseded by NIST SP 800-61r3 in April 2025, and SANS teaches six. The second trap is stale framework names: as of ATT&CK v19 there are 15 Enterprise tactics, and the tactic once called Defense Evasion is now Stealth (MITRE ATT&CK tactics, checked October 2026). Prep written for CS0-003 still says 14. Then the look-alikes: containment vs eradication vs recovery, chain of custody and order of volatility.

Tip: on any what-next ticket, name the current step before reading the options. The right answer is the next step, very rarely two ahead.

Reporting and Communication: audience first

Domain 4 is 16% of CS0-004 and has two objectives. Vulnerability reporting (4.1) covers scan reports, risk scorecards, action plans and the inhibitors that stall a fix, such as a legacy system or a business process that cannot stop. Incident reporting and communication (4.2) covers declaration and escalation, the communication plan, lessons learned, shift handover and the metrics a SOC reports.

The trap is audience. An executive summary carries impact, risk and the decision needed; a technical report carries evidence and the fix. Executive summary vs technical report draws the line. The metrics come in near-identical names, mean time to detect, to respond, to remediate and to close, and MTTD vs MTTR vs MTTC pulls them apart.

Tip: this domain is vocabulary plus judgment, small enough for a few sessions. Pair the two drills with the CySA+ flashcards for the metric names.

What changed from CS0-003

CS0-003 and CS0-004 objectives side by side, checked October 2026
ItemCS0-003CS0-004
Objectives per domain5 / 5 / 3 / 26 / 4 / 3 / 2
Domain weights33 / 30 / 20 / 17%34 / 26 / 24 / 16%
AI in security operationsNo objectiveObjective 1.6
Attack mitigation (XSS, injection…)Its own objective, 2.4Folded into secure coding
Incident responseSplit over 3.2 and 3.3One ordered process, 3.2
Newly named—EPSS, SBOM, SCA, STRIDE, LOLBins
English examUntil Dec 22, 2026Since June 23, 2026

Sources: CS0-003 exam objectives, CS0-004 exam objectives and CompTIA CS0-003 page. The full comparison is on CS0-004 vs CS0-003.

Scenario objectives are where hands-on questions liveRule

Objectives 1.2, 1.3, 2.1, 2.2, 2.3 and 3.3 open with "Given a scenario". CompTIA does not map performance-based questions (PBQs) to objectives, but the PBQ tasks it lists, such as analyzing SIEM alerts, reviewing logs and prioritizing vulnerabilities, sit in those objectives (CompTIA FAQ, June 12, 2026). That link is our reading; CySA+ PBQs covers what to practice.

Every area and concept, by domain

Areas sit under their domain, and each area lists the concept pages that split its look-alikes. Every area page has its own drill.

A route through the guide

  1. Start with the heaviest domain

    Security Operations is 34%, and its indicators area feeds tickets in every other domain.

  2. One area at a time

    Read the guide, run the drill, then open the concept page behind any note you got wrong.

  3. Mix the domains

    Once every area has had a pass, move to the mixed CySA+ practice test and filter by your weakest chips.

  4. Put it on a calendar

    The CySA+ study plan spreads the areas over 4, 8 or 12 weeks by domain weight and finishes on a mock.

Exam facts, checked against the source

Length, score, price and retake rules, each with its source and the date it was checked.

Getting certified

CySA+ has no required prerequisites. CompTIA recommends about four years of hands-on work as a SOC or vulnerability analyst (CS0-004 exam objectives, checked October 2026).

Compare and prepare

CySA+ beside Security+, PenTest+, CISSP and SecurityX, the prep resources that exist for CS0-004, the flashcard deck and the week-by-week study plan.

Sources

  1. CompTIA CySA+ CS0-004 exam objectives, version 2.0 (PDF) (checked October 9, 2026)
  2. CompTIA CySA+ CS0-003 exam objectives (PDF) (checked October 9, 2026)
  3. CompTIA CySA+ V4 (CS0-004) exam page (checked October 9, 2026)
  4. CompTIA CySA+ V3 (CS0-003) exam page · CS0-003 retirement dates (checked October 9, 2026)
  5. CompTIA blog: The New CompTIA CySA+ (V4), Your Certification Questions Answered · published June 12, 2026 (checked October 9, 2026)
  6. FIRST, CVSS v4.0 specification (checked October 9, 2026)
  7. FIRST, Exploit Prediction Scoring System (EPSS) (checked October 9, 2026)
  8. NIST, SP 800-61r3 (checked October 9, 2026)
  9. MITRE, ATT&CK Enterprise tactics (v19) (checked October 9, 2026)

Study between shifts

This site's practice app puts CySA+ questions on your phone. Available for iPhone and Android.