All certifications / CySA+ / Lessons
CySA+ CS0-004 lessons
Study CySA+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CySA+ study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Security operations
- System and network architecture: on-prem, cloud, hybrid, serverless, containers, segmentation, zero trust, SASE
- Identity and access: MFA, SSO, federation, PAM, just-in-time access, CASB
- Logging: log ingestion, time synchronization (NTP), log levels, Windows Event IDs, Sysmon, Linux auth logs
- Network indicators: beaconing, unusual bandwidth, irregular peer-to-peer traffic, rogue devices, scans, unexpected ports
- Host indicators: unusual processes, masquerading binaries, unauthorized software, persistence (services, scheduled tasks, run keys)
- Application indicators: anomalous activity, new accounts, unexpected output, injection strings in web logs
- Tools: SIEM, SOAR, EDR, Wireshark/tcpdump, sandboxing, CyberChef, reputation and WHOIS lookups
- Email analysis: headers, SPF, DKIM, DMARC, impersonation and malicious attachments
- Threat intelligence: actor types, TTPs, confidence (timeliness, relevancy, accuracy), open vs closed sources, ISACs, STIX/TAXII
- Threat hunting: hypotheses, IoC collection, focus areas, active defense and honeypots
- Process improvement: standardizing processes, automation and orchestration, tuning alerts, single pane of glass, safe use of AI assistants
Domain 2: Vulnerability management
- Asset discovery and scan types: active vs passive, credentialed vs non-credentialed, agent vs agentless, internal vs external
- Special environments: OT/ICS, cloud, mobile and scanning without disrupting production
- Scanner and tool output: Nessus/OpenVAS reports, nmap, web app scanners, SAST, DAST, SCA, fuzzing, cloud posture tools
- Validating results: true/false positives and negatives, backported patches
- Prioritization: CVSS base metrics and vectors, EPSS, CISA KEV, asset value, exploitability, context
- Common software vulnerabilities: injection, XSS, SSRF, IDOR, broken access control, buffer overflow, insecure cookies
- Recommending controls: input validation, output encoding, parameterized queries, memory protections, secure coding
- Compensating controls, segmentation and exceptions for systems that cannot be patched
- Vulnerability response: patching, configuration management, change management, maintenance windows
- Risk management: accept, avoid, transfer, mitigate; inhibitors to remediation (legacy systems, business process interruption, MOUs/SLAs)
Domain 3: Incident response & management
- Attack frameworks: Cyber Kill Chain, Diamond Model, MITRE ATT&CK, OWASP Testing Guide, OSSTMM
- IR lifecycle (NIST SP 800-61): preparation; detection and analysis; containment, eradication and recovery; post-incident activity
- Detection and analysis: IoCs, scoping, impact, severity and triage
- Evidence acquisition: order of volatility, chain of custody, legal hold, forensic imaging and hash validation
- Memory and disk analysis basics: Volatility, FTK Imager, Autopsy
- Containment strategies: isolation, segmentation, and when to watch before acting
- Eradication and recovery: reimaging, removing persistence, restoring from clean backups, patching the entry point
- Preparation: IR plan, playbooks, tools, training, tabletop exercises, out-of-band communication
- Post-incident activity: root cause analysis, lessons learned, updating playbooks and controls
Domain 4: Reporting & communication
- Vulnerability reports: affected hosts, risk scores, mitigation, recurrence, prioritization
- Compliance reports, action plans, exceptions and compensating controls
- Metrics and KPIs: trends, top 10 lists, critical vulnerabilities, zero-days, SLA compliance
- Stakeholder identification and communication: technical teams, system owners, executives
- Incident response communication: legal, HR, public relations, regulators, law enforcement, customers
- Incident declaration and escalation paths
- Incident reports: executive summary, who/what/when/where/why, timeline, impact, scope, evidence, recommendations
- Root cause analysis and lessons learned feeding back into reporting
- Response metrics: mean time to detect, respond and remediate; alert volume