CompTIA CySA+ (CS0-003) Exam Blueprint

CS0-003

85Questions
165 minDuration
750/100-900Passing Score
$404Price
3 yearsValid For
4Languages
Practice CompTIA CySA+ on QuizForge

Exam Domains

1.0 Security Operations 33%
  • 1.1System and network architecture
    Explaining log ingestion, operating system (OS) concepts, infrastructure, network architecture, identity and access management (IAM), encryption, and sensitive data protection
  • 1.2Malicious activity indicators
    Analyzing network anomalies like bandwidth spikes and rogue devices, host issues like unauthorized software and data exfiltration, application irregularities like unexpected communication and service interruptions, and threats like social engineering attacks
  • 1.3Tools and techniques
    Detecting malicious activity using tools like Wireshark, security information and event management (SIEM), and VirusTotal, along with techniques like pattern recognition and email analysis, supported by scripting languages like Python and PowerShell
  • 1.4Threat intelligence and hunting
    Comparing threat actors, tactics, techniques, and procedures (TTP); confidence levels; collection methods; intelligence sharing; and hunting techniques
  • 1.5Process improvement
    Standardizing processes, streamlining operations, integrating tools, and using a single pane of glass
2.0 Vulnerability Management 30%
  • 2.1Vulnerability scanning
    Implementing asset discovery, internal vs. external scanning, agent vs. agentless, credentialed vs. non-credentialed, passive vs. active, static vs. dynamic, and critical infrastructure scanning
  • 2.2Assessment tool output
    Analyzing network scanning, web application scanners, vulnerability scanners, debuggers, multipurpose tools, and cloud infrastructure assessments
  • 2.3Vulnerability prioritization
    Interpreting common vulnerability scoring system (CVSS), validating findings, assessing exploitability, and considering asset value and zero-day vulnerabilities
  • 2.4Mitigation controls
    Recommending controls for cross-site scripting (XSS), overflow vulnerabilities, and data poisoning
  • 2.5Vulnerability response
    Explaining compensating controls, patching, configuration management, maintenance windows, exceptions, governance, service-level objectives (SLOs), secure software development life cycle (SDLC), and threat modeling
3.0 Incident Response Management 20%
  • 3.1Attack methodology frameworks
    Explaining cyber kill chains, diamond model of intrusion analysis, MITRE ATT&CK, Open Source Security Testing Methodology Manual (OSSTMM), and OWASP testing guide
  • 3.2Incident response activities
    Performing detection, analysis, containment, eradication, and recovery
  • 3.3Incident management life cycle
    Explaining incident response plans, tools, playbooks, tabletop exercises, training, business continuity (BC), disaster recovery (DR), forensic analysis, and root cause analysis
4.0 Reporting and Communication 17%
  • 4.1Vulnerability management reporting
    Explaining compliance reports, action plans, inhibitors to remediation, metrics, key performance indicators (KPIs), and stakeholder communication
  • 4.2Incident response reporting
    Explaining incident declaration, escalation, reporting, communication, root cause analysis, lessons learned, and metrics and KPIs

Exam Details

Question TypesMultiple Choice (single), Multiple Choice (multiple), Performance-Based
FormatLinear
Online ProctoringAvailable
ID RequirementsTwo forms of ID are required. Primary ID must be government-issued, include candidate's name, photo, and signature (e.g. passport, driver's license). Secondary ID must include candidate's name and signature or name and photo.
RenewalRequired -- Earn CE credits through CompTIA CE program (training, conferences, publishing, teaching, higher certs) or retake the current exam version before expiry.
PrerequisitesNetwork+, Security+, or equivalent knowledge (recommended)
Retake PolicyNo waiting period required before first retake. After the second failed attempt, candidates must wait 14 calendar days before any subsequent attempt. No limit on total attempts.
LanguagesEnglish, Japanese, Portuguese, Simplified Chinese

Official Study Resources

online courseCertMaster Learn ($499)
practice examCertMaster Practice ($99)
labCertMaster Labs ($199)