Credential type: certification examination · verified on the issuer's site September 20, 2026 issuer page
What This Exam Validates
CompTIA CySA+ is a professional certification covering security operations, vulnerability management, incident response, and reporting. It evaluates technical proficiency in identifying and managing security threats within an organizational environment. CompTIA administers this exam, which consists of 85 questions. The exam is scheduled for retirement on 2026-12-22, and candidates should transition their preparation to the successor, CS0-004 (CompTIA CySA+ (V4)), to ensure their skills remain current with the latest industry standards and professional requirements for cybersecurity analysts.
Who Should Take This Exam
This exam is intended for security analysts, incident responders, and threat hunters. It requires practical experience in monitoring network traffic, analyzing vulnerability scan results, and managing incident response life cycles within a professional organizational environment to successfully pass the assessment.
Skills You Should Be Ready to Demonstrate
- System and network architecture analysis
- Malicious activity detection
- Vulnerability scanning and prioritization
- Incident response management
- Security reporting and communication
How to Prepare Before Retirement
Review the four domains, which carry weights of 33%, 30%, 20%, and 17% respectively. Utilize official CompTIA study documentation and practice labs to gain hands-on experience with the 85 questions. Since this exam retires on 2026-12-22, focus your efforts on the objectives for the successor, CS0-004, to ensure your knowledge remains current with the latest certification standards and professional requirements for cybersecurity analysts.
Domain Study Guidance
Security Operations: Study Guidance
This domain covers the technical aspects of security operations, focusing on how network architecture and security tools identify malicious activity indicators. It provides the knowledge of the systems and techniques required to maintain a secure environment.
- System and network architecture
- Malicious activity indicators
- Tools and techniques
Vulnerability Management: Study Guidance
This domain addresses the identification and management of vulnerabilities through scanning, assessment, and prioritization techniques. It emphasizes the use of assessment tool output to effectively manage and mitigate security risks within the organizational network infrastructure.
- Vulnerability scanning
- Assessment tool output
- Vulnerability prioritization
Incident Response Management: Study Guidance
This domain focuses on the incident response life cycle, including frameworks for managing and responding to security incidents. It covers the activities and methodologies required to handle security threats and maintain operational continuity during an active incident.
- Attack methodology frameworks
- Incident response activities
- Incident management life cycle
Reporting and Communication: Study Guidance
This domain covers the communication and reporting requirements for both vulnerability management and incident response activities. It ensures that security professionals can document and communicate findings to stakeholders to support informed decision-making and organizational security posture.
- Vulnerability management reporting
- Incident response reporting
Exam-Day Guidance
The exam uses a linear format with 85 questions, including multiple choice and performance-based items. You have 165 minutes to complete the assessment. Ensure you manage your time effectively across all four domains to reach the passing score of 750.
Frequently asked questions
How many questions are on the exam?
The exam consists of 85 questions in a linear format. These questions include multiple choice (single), multiple choice (multiple), and performance-based items to test your skills during the allotted time.
What is the passing score?
The passing score for this exam is 750 on a scale of 100-900. Candidates must achieve this score to successfully earn the CompTIA CySA+ certification and demonstrate their professional proficiency.
How long is the exam?
The total duration for the exam is 165 minutes. This time limit is designed to allow candidates to complete all 85 questions in the linear format provided by the testing center.
What is the exam price?
The exam price is $404. This fee covers the cost of the certification attempt and is payable through the official CompTIA website for all registered candidates seeking to earn this credential.
Sources and Verification
Verified 2026-08-30
How this page was made
This editorial was constructed by synthesizing verified exam facts provided by CompTIA and referencing official documentation regarding the retirement and successor path to ensure accuracy for all candidates preparing for certification.
Exam Domains
1.0 Security Operations
33%
- 1.1System and network architecture
Explaining log ingestion, operating system (OS) concepts, infrastructure, network architecture, identity and access management (IAM), encryption, and sensitive data protection
- 1.2Malicious activity indicators
Analyzing network anomalies like bandwidth spikes and rogue devices, host issues like unauthorized software and data exfiltration, application irregularities like unexpected communication and service interruptions, and threats like social engineering attacks
- 1.3Tools and techniques
Detecting malicious activity using tools like Wireshark, security information and event management (SIEM), and VirusTotal, along with techniques like pattern recognition and email analysis, supported by scripting languages like Python and PowerShell
- 1.4Threat intelligence and hunting
Comparing threat actors, tactics, techniques, and procedures (TTP); confidence levels; collection methods; intelligence sharing; and hunting techniques
- 1.5Process improvement
Standardizing processes, streamlining operations, integrating tools, and using a single pane of glass
2.0 Vulnerability Management
30%
- 2.1Vulnerability scanning
Implementing asset discovery, internal vs. external scanning, agent vs. agentless, credentialed vs. non-credentialed, passive vs. active, static vs. dynamic, and critical infrastructure scanning
- 2.2Assessment tool output
Analyzing network scanning, web application scanners, vulnerability scanners, debuggers, multipurpose tools, and cloud infrastructure assessments
- 2.3Vulnerability prioritization
Interpreting common vulnerability scoring system (CVSS), validating findings, assessing exploitability, and considering asset value and zero-day vulnerabilities
- 2.4Mitigation controls
Recommending controls for cross-site scripting (XSS), overflow vulnerabilities, and data poisoning
- 2.5Vulnerability response
Explaining compensating controls, patching, configuration management, maintenance windows, exceptions, governance, service-level objectives (SLOs), secure software development life cycle (SDLC), and threat modeling
3.0 Incident Response Management
20%
- 3.1Attack methodology frameworks
Explaining cyber kill chains, diamond model of intrusion analysis, MITRE ATT&CK, Open Source Security Testing Methodology Manual (OSSTMM), and OWASP testing guide
- 3.2Incident response activities
Performing detection, analysis, containment, eradication, and recovery
- 3.3Incident management life cycle
Explaining incident response plans, tools, playbooks, tabletop exercises, training, business continuity (BC), disaster recovery (DR), forensic analysis, and root cause analysis
4.0 Reporting and Communication
17%
- 4.1Vulnerability management reporting
Explaining compliance reports, action plans, inhibitors to remediation, metrics, key performance indicators (KPIs), and stakeholder communication
- 4.2Incident response reporting
Explaining incident declaration, escalation, reporting, communication, root cause analysis, lessons learned, and metrics and KPIs
Exam Details
Question TypesMultiple Choice (single), Multiple Choice (multiple), Performance-Based
FormatLinear
Online ProctoringAvailable
ID RequirementsTwo forms of ID are required. Primary ID must be government-issued, include candidate's name, photo, and signature (e.g. passport, driver's license). Secondary ID must include candidate's name and signature or name and photo.
RenewalRequired -- Earn CE credits through CompTIA CE program (training, conferences, publishing, teaching, higher certs) or retake the current exam version before expiry.
PrerequisitesNetwork+, Security+, or equivalent knowledge (recommended)
Retake PolicyNo waiting period required before first retake. After the second failed attempt, candidates must wait 14 calendar days before any subsequent attempt. No limit on total attempts.
LanguagesEnglish, Japanese, Portuguese, Simplified Chinese