Certification Prep

CompTIA CySA+

Certification Prep

The CompTIA CySA+ certification prep path will provide you with a comprehensive overview of the cybersecurity principles and security best practices you’ll need to pass the CySA+ certification exam.

Path Releasing Q2 2025
Full access included with 
Cybrary Insider Pro
 and 
Teams

43

H

5

M
Time

Intermediate

i
Designed for learners with a solid grasp of foundational IT and cybersecurity concepts who are interested in pursuing an entry-level security role.
Experience Level

38

i

Earn qualifying credits for certification renewal with completion certificates provided for submission.
CEU's

Enrollees

Learners at 96% of Fortune 1000 companies trust Cybrary

About this Path

CompTIA Cybersecurity Analyst, or CySA+, is a globally recognized certification that validates the competencies required for Cybersecurity Analysts. CySA+ is often used as a requirement for positions such as Security Analyst, Threat Intelligence Analyst, and SOC Analyst.

Cybrary’s CompTIA CySA+ certification course provides the foundational knowledge you’ll need for the CySA+ exam. Topics include security operations, vulnerability management, incident response, reporting, and more.

Read More

Skills you'll gain

Path Outline

Collection Outline

Coming Soon

The Leadership and Management Career Path is expected to release in Q2 of 2025. Sign up now to explore our other leadership courses and content.

Start Learning for Free
1

Learn

Learn core concepts and get hands-on with key skills.

COURSE
COURSE
COURSE
COURSE
COURSE
COURSE
COURSE
CySA+: Security Operations
4
H
41
M

In this CompTIA Cybersecurity Analyst (CySA+ CS0-003): Security Operations course you will learn about system and network architecture in security operations, how to analyze indicators of potentially malicious activity, and about the tools and techniques used for determining malicious activity.

COURSE
COURSE
COURSE
COURSE
COURSE
COURSE
COURSE
CySA+: Vulnerability Management
2
H
8
M

In this CompTIA Cybersecurity Analyst (CySA+ CS0-003): Vulnerability Management course, you will learn about analyzing output from vulnerability assessment tools, controls to mitigate attacks and software vulnerabilities, and vulnerability response, handling, and management.

COURSE
COURSE
COURSE
COURSE
COURSE
COURSE
COURSE
CySA+: Incident Response and Management
H
49
M

In this CompTIA Cybersecurity Analyst (CySA+ CS0-003): Incident Response and Management course, you will learn about attack methodology frameworks, performing incident response activities, and preparation and post-incident phases.

COURSE
COURSE
COURSE
COURSE
COURSE
COURSE
COURSE
CySA+: Reporting and Communication
H
41
M

In this CompTIA Cybersecurity Analyst (CySA+ CS0-003): Reporting and Communication course, you will learn about the importance of vulnerability management reporting and incident response reporting.

2

Practice

Exercise your problem-solving and creative thinking skills with security-centric puzzles

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Nmap Basics
1
H
10
M

In this hands-on lab, you will learn the basics of Nmap, including basic functionality and practical applications. You will practice scanning and enumeration using a range of different Nmap options.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Security Ticketing
1
H
15
M

In this hands-on lab, you will learn the basics of security ticketing, including the core components of a security ticket and how they can be resolved. You will practice navigating a security ticketing platform, and create, edit, and close tickets in that platform.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Log Analysis Basics
1
H
30
M

In this hands-on lab, you will learn the basics of log analysis, including key terms and basic anatomy. You will practice using the command line to conduct simple analysis techniques on a series of log files, including profiling and search.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Vulnerability Scanner Basics
1
H
5
M

In this hands-on lab, you will learn the basics of vulnerability scanners, including basic functionality and practical applications. You will practice configuring and analyzing scans using the OpenVAS vulnerability scanner.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Patching Basics
1
H
5
M

In this hands-on lab, you will learn the basics of vulnerability scanners, including basic functionality and practical applications. You will practice configuring and analyzing scans using the OpenVAS vulnerability scanner

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Windows Event Logs
1
H
10
M

In this hands-on lab, you will learn the basics of Windows Event logs, their format, and different types. You will practice using the Event Viewer and correlating between Event Logs in the Event Viewer and a SIEM

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
SIEM Search Expressions
1
H
10
M

In this hands-on lab, you will learn the basics of using search expressions in a SIEM. You will practice creating a series of search expressions in the Wazuh SIEM.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Network Observables
1
H
10
M

In this hands-on lab, you will learn the basics of network observables. You will practice researching and documenting observables from a suspicious email using the security ticketing system theHive.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Burp Suite Basics
1
H
20
M

In this hands-on lab, you will learn the basics of Burp Suite, a popular web application penetration testing tool. You will practice using some core features of Burp Suite to identify and exploit vulnerabilities in a web application.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
SIEM Detection and Alerting
1
H
15
M

In this hands-on lab, you will learn the basics of SIEM-based detection and alerting. You will practice using the Wazuh SIEM to create, modify, and test custom rules and alerts.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Web Activity Logs
1
H
15
M

In this hands-on lab, you will learn the basics of web activity logs. You will then practice identifying meaningful events in web proxy (HTTP/HTTPS) and name server (DNS) logs in the context of a new threat intelligence report.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
EDR Basics
1
H
10
M

In this hands-on lab, you will learn the basics of Endpoint Detection and Response tools. You will practice using the Wazuh EDR to install an agent on a Windows endpoint and detect simulated attacks aligned to the MITRE ATT&CK framework.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
SIEM Dashboards
1
H
30
M

In this lab, you will learn the basics of SIEM dashboards. You will practice creating your own custom dashboard using the Wazuh SIEM.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Cryptography Basics
0
H
30
M

In this hands-on lab, you will learn about the basics of cryptography and the cryptographic process. You will practice encrypting and decrypting messages using a simple simple ciphe

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Spearphishing with a Link
1
H
30
M

In this hands-on lab, you will learn how to analyze spearphishing emails containing malicious links. You will practice analyzing a sample spearphishing email.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Symmetric Cryptography
0
H
55
M

In this hands-on lab, you will learn about the basics of symmetric cryptography. You will practice encrypting and decrypting messages using symmetric cryptography.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Wireshark Basics
1
H
15
M

In this hands-on lab, you will learn the basics of Wireshark, including basic functionality and practical applications. You will practice packet capture and analysis using a range of different protocols and Wireshark features, including display filters, streams, and conversation filters.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Execution in Windows
1
H
20
M

In this hands-on lab, you will learn the basics of process analysis and Windows execution. You will practice using Process Explorer and a SIEM to analyze information from collected process dumps.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Asymmetric Cryptography
1
H
5
M

In this hands-on lab, you will learn about the basics of asymmetric cryptography. You will practice encrypting and decrypting messages using asymmetric cryptography.

Persistence via Windows Services
1
H
25
M
Windows Services are the main vehicle used by the Windows OS to start and run background functions that do not require user interaction. Configuring malware to run as a service is a common strategy for trying to blend malicious code execution in with other legitimate Windows functions. Prevent adversaries from gaining persistence in this course.
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Cryptographic Hash Functions
1
H
0
M

In this hands-on lab, you will learn about the basics of cryptographic hash functions. You will practice generating and comparing hash values.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Spearphishing with an Attachment
1
H
45
M

In this hands-on lab, you will learn the basics of email analysis with a special focus on malicious attachments. You will practice performing triage analysis of a spearphishing email containing a suspicious attachment.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Local Authentication in Windows
1
H
10
M

In this hands-on lab, you will learn about local authentication mechanics in the Windows operating system, including user accounts, the authentication process, and different types of authentication. You will practice identifying when a user account has logged on and logged off, including the type of authentication.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Domain Authentication in Windows
1
H
25
M

In this hands-on lab, you will learn about domain-based authentication mechanics in the Windows operating system, including user accounts, the authentication process, and different types of authentication. You will practice identifying when a domain user account has logged on and logged off, including the type of authentication.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
SIEM Basics
1
H
M

In this hands-on lab, you will learn the basics of SIEMs, including basic functionality and practical applications. You will practice analyzing log files using the Wazuh SIEM.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Metasploit Basics
1
H
15
M

In this hands-on lab, you will learn the basics of Metasploit, a popular penetration testing tool. You will practice using some core features of Metasploit to identify and exploit vulnerabilities on a live server.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Incident Response Basics
1
H
10
M

In this hands-on lab, you will learn the basics of Incident Response, including its role in a security program and major phases. You will practice using incident response tools on a live system to capture memory and essential system files for further investigation.

VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
VIRTUAL LAB
Digital Forensics Basics
1
H
M

In this hands-on lab, you will learn the basics of digital forensics, including its role in an investigation and major phases. You will practice using the Autopsy forensics tool to analyze and retrieve evidence from a

3

Prove

Assess your knowledge and skills to identify areas for improvement and measure your growth

CyberVista Practice Test
CyberVista Practice Test
CyberVista Practice Test
CyberVista Practice Test
CyberVista Practice Test
CyberVista Practice Test
CompTIA Cybersecurity Analyst (CySA+) CS0-003
1
H
M

The CySA+ practice test helps students prepare for the CompTIA CySA+ CS0-003 certification exam. The CySA+ certification prepares students for careers in security analyst roles and is an approved certification under DOD 8570.

4

Train Your Team

Cybrary’s expert-led cybersecurity courses help your team remediate skill gaps and get up-to-date on certifications. Utilize Cybrary to stay ahead of emerging threats and provide team members with clarity on how to learn, grow, and advance their careers within your organization.

Instructors

Chris Daywalt
Security Freelancer
Read Full Bio
Joseph White
Lab Architect
Read Full Bio
Garret Donaldson
Lab Architect
Read Full Bio
Marc Balingit
Security Research
Read Full Bio
Owen Dubiel
Security Engineer
Read Full Bio

Get Hands-on Learning

Put your skills to the test in virtual labs, challenges, and simulated environments.

Measure Your Progress

Track your skills development from lesson to lesson using the Cybrary Skills Tracker.

Connect with the Community

Connect with peers and mentors through our supportive community of cybersecurity professionals.

Success from Our Learners

"Becoming a Cybrary Insider Pro was a total game changer. Cybrary was instrumental in helping me break into cybersecurity, despite having no prior IT experience or security-related degree. Their career paths gave me clear direction, the instructors had real-world experience, and the virtual labs let me gain hands-on skills I could confidently put on my resume and speak to in interviews."

Cassandra

Information Security Analyst/Cisco Systems

"I was able to earn both my Security+ and CySA+ in two months. I give all the credit to Cybrary. I’m also proud to announce I recently accepted a job as a Cyber Systems Engineer at BDO... I always try to debunk the idea that you can't get a job without experience or a degree."

Casey

Cyber Systems Engineer/BDO

"Cybrary has helped me improve my hands-on skills and pass my toughest certification exams, enabling me to achieve 13 advanced certifications and successfully launch my own business. I love the practice tests for certification exams, especially, and appreciate the wide-ranging training options that let me find the best fit for my goals"

Angel

Founder,/ IntellChromatics.

"Cybrary really helped me get up to speed and acquire a baseline level of technical knowledge. It offers a far more comprehensive approach than just learning from a book. It actually shows you how to apply cybersecurity processes in a hands-on way"

Don Gates

Principal Systems Engineer/SAIC

"Cybrary’s SOC Analyst career path was the difference maker, and was instrumental in me landing my new job. I was able to show the employer that I had the right knowledge and the hands-on skills to execute the role."

Cory

Cybersecurity analyst/

"I was able to earn my CISSP certification within 60 days of signing up for Cybrary Insider Pro and got hired as a Security Analyst conducting security assessments and penetration testing within 120 days. This certainly wouldn’t have been possible without the support of the Cybrary mentor community."

Mike

Security Engineer and Pentester/

"Becoming a Cybrary Insider Pro was a total game changer. Cybrary was instrumental in helping me break into cybersecurity, despite having no prior IT experience or security-related degree. Their career paths gave me clear direction, the instructors had real-world experience, and the virtual labs let me gain hands-on skills I could confidently put on my resume and speak to in interviews."

Cassandra

Information Security Analyst/Cisco Systems

"I was able to earn both my Security+ and CySA+ in two months. I give all the credit to Cybrary. I’m also proud to announce I recently accepted a job as a Cyber Systems Engineer at BDO... I always try to debunk the idea that you can't get a job without experience or a degree."

Casey

Cyber Systems Engineer/BDO

"Cybrary has helped me improve my hands-on skills and pass my toughest certification exams, enabling me to achieve 13 advanced certifications and successfully launch my own business. I love the practice tests for certification exams, especially, and appreciate the wide-ranging training options that let me find the best fit for my goals"

Angel

Founder,/ IntellChromatics.

Frequently Asked Questions

Who is this for?

This certification prep path is designed for mid-to-advanced career practitioners who are interested in earning their CySA+ certification. 

There are no prerequisites for Cybrary’s CySA+ training course, but you will need four years of hands-on experience in incident response or related cybersecurity roles  to obtain certification. CompTIA recommends earning your Network+ or Security+ certification before pursuing CySA+.

Which versions of the exam are supported?

This certification prep path is aligned with the CS0-003 version of CySA+, released in June 2023.

Why should I get CompTIA CySA+ certified?

The CompTIA CySA+ certification is the industry standard for Cybersecurity Analysts. CySA+ validates your ability to perform data analysis and interpret the results to identify vulnerabilities, threats and risks to an organization.

CySA+ demonstrates to employers that you have the skill required for a role in threat detection, incident response, or vulnerability management.

What is on the CompTIA CySA+ exam?

The CompTIA CySA+ exam contains multiple choice and performance-based questions on topics related to threat detection and analysis, threat management, incident response, and reporting. Cybrary’s CySA+ certification prep path covers all relevant topics and includes both labs for hands-on practice and a practice test that will ensure you’re ready for the official certification exam.

What jobs can I get with CompTIA CySA+ certification?

Earning your CySA+ certification will prepare you for a variety of cybersecurity roles, including security operations center (SOC) analyst, vulnerability analyst, cybersecurity specialist, threat intelligence analyst, security engineer, and more. CySA+ is an ideal advanced certification for validating your existing knowledge and growing your career in security analytics.