Index
# 🔵 CompTIA CySA+ — Study Hub
### A source-grounded study hub for **CompTIA CySA+ (CS0-003)**
*Concepts, real diagrams, and exam prep* — the **vendor-neutral, defensive (blue-team / SOC
analyst)** certification for detection, threat hunting, and incident response.





[!NOTE] Unofficial & no fabrication. Not affiliated with or endorsed by CompTIA. Exam specifics are from CompTIA's official CySA+ page; volatile items (price, exam code, CEU renewal) should be re-checked there — codes rotate ~every 3 years. Compiled 2026-06-20.
📋 At a glance¶
| Item | Detail |
|---|---|
| Exam | CS0-003 (verify — codes rotate) |
| Format | Max 85 questions — multiple-choice + performance-based (PBQ) |
| Duration / pass | 165 minutes · 750 on a 100–900 scale |
| Level / focus | Intermediate, vendor-neutral, defensive (SOC analyst / detection & response) |
| Recommended | Security+ and ~4 years hands-on experience (not required) |
Full details: exam & objectives.
🗺️ The four domains¶
flowchart LR
D1["1 · Security<br/>Operations — 33%"] --> D2["2 · Vulnerability<br/>Management — 30%"]
D2 --> D3["3 · Incident Response<br/>& Management — 20%"]
D3 --> D4["4 · Reporting &<br/>Communication — 17%"]
| # | Domain | Weight | Page |
|---|---|---|---|
| 1 | Security Operations | 33% | 01-security-operations.md |
| 2 | Vulnerability Management | 30% | 02-vulnerability-management.md |
| 3 | Incident Response and Management | 20% | 03-incident-response-and-management.md |
| 4 | Reporting and Communication | 17% | 04-reporting-and-communication.md |
📦 What's inside¶
| Section | Contents |
|---|---|
| Overview | What is CySA+ · Exam & objectives |
| The 4 domains | SOC operations, vulnerability management, incident response, reporting — taught to the CS0-003 objectives |
| Exam prep | Study plan · Practice questions |
| Reference | Glossary (SOC / blue-team terms) — acronyms cross-link the Security+ list |
🧭 Where it fits¶
CySA+ is the detection-and-response analyst credential — the blue-team counterpart to the offensive CEH and PenTest+ hubs, and a natural step after Security+.
- Operationalizes the monitoring, SIEM, and incident-response topics from Security+ Domain 4.
- Pairs with the attack → defense matrix: CySA+ is the defender reading the telemetry the attacks generate.
- Connects to PAM — privileged-session monitoring and audit (WALLIX deep dives) feed SOC detection.
🔗 Quick links¶
CompTIA and CySA+ are trademarks of CompTIA, used here for identification and educational purposes only.