CompTIA Cybersecurity Analyst (CySA+)
Credential: CompTIA Cybersecurity Analyst (CySA+)
Credentialing Agency: Computing Technology Industry Association (CompTIA)
Renewal Period: 3 years
The CompTIA, Cybersecurity Analyst (CySA+) uses continuous security monitoring to apply behavioral analytics to devices and networks to prevent, detect and combat cybersecurity threats. CySA+ certification validates that the professional has the knowledge and skills required to leverage threat detection techniques and intelligence, find and address vulnerabilities, analyze and interpret data, recommend preventative actions, and successfully respond to and recover from incidents. While there is no required prerequisite, CySA+ is intended to follow CompTIA Security+ or equivalent experience and has a technical, hands-on focus. Candidates must pass a written exam.
More information can be found on the certifying agency's website.
CompTIA Cybersecurity Analyst (CySA+)
MINIMUM REQUIREMENTS
Attainability:
Eligibility Requirements (View Details)
- Credential Prerequisite
- Experience: 4 years recommended
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for a Service member to meet eligibility requirements. Requirements listed here are based on the minimum degree required.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
Exam Administration (View Details)
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
RECERTIFICATION SUMMARY
Renewal Period: 3 years
AGENCY CONTACT INFORMATION
Computing Technology Industry Association (CompTIA)
3500 Lacey Road
Suite 100
Downers Grove, IL 60515
Phone: 866.835.8020
Fax: 630.678.8300
Contact Page
Written Exam CS0-002
-
1.0 Threat and Vulnerability Management (22%)
- 1.1 Explain the importance of threat data and intelligence.
- 1.2 Given a scenario, utilize threat intelligence to support organizational security.
- 1.3 Given a scenario, perform vulnerability management activities.
- 1.4 Given a scenario, analyze the output from common vulnerability assessment tools.
- 1.5 Explain the threats and vulnerabilities associated with specialized technology.
- 1.6 Explain the threats and vulnerabilities associated with operating in the cloud.
- 1.7 Given a scenario, implement controls to mitigate attacks and software vulnerabilities.
-
2.0 Software and Systems Security (18%)
- 2.1 Given a scenario, apply security solutions for infrastructure management.
- 2.2 Explain software assurance best practices.
- 2.3 Explain hardware assurance best practices.
-
3.0 Security Operations and Monitoring (25%)
- 3.1 Given a scenario, analyze data as part of security monitoring activities.
- 3.2 Given a scenario, implement configuration changes to existing controls to improve security.
- 3.3 Explain the importance of proactive threat hunting.
- 3.4 Compare and contrast automation concepts and technologies.
-
4.0 Incident Response (22%)
- 4.1 Explain the importance of the incident response process.
- 4.2 Given a scenario, apply the appropriate incident response procedure.
- 4.3 Given an incident, analyze potential indicators of compromise.
- 4.4 Given a scenario, utilize basic digital forensics techniques.
-
5.0 Compliance and Assessment (13%)
- 5.1 Understand the importance of data privacy and protection.
- 5.2 Given a scenario, apply security concepts in support of organizational risk mitigation.
- 5.3 Explain the importance of frameworks, policies, procedures, and controls.
Exam Preparation Resources
There are a number of resources available to help you prepare for the CompTIA Cybersecurity Analyst (CySA+) examination:
- Best Sources
- Related Training
An additional resource is O'Reilly Learning Safari Books Online, a searchable digital library that provides online access to thousands of books, training videos and conference sessions. See the Educational Resources section on the Related Sites page here on COOL to learn how to get free access.
Testing Information
-
Exam Administration
Credential exams may be administered in-person at a testing site, proctored on-line remotely, or have options for both. If an exam is administered through a test vendor, the third-party test vendor box will be checked. The following test administration options apply to the CompTIA Cybersecurity Analyst (CySA+) credential where checked:
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
For more information on the Computing Technology Industry Association (CompTIA) testing process, visit the agency website.
-
Third-Party Test Vendor Information
Testing for this credential is handled by the following vendor:
Pearson VUE
The test centers are located in the U.S. They also have some test centers on military bases.
To find out more, use the following links on the Pearson VUE website:
- Search for Testing Program
- Learn About Testing for Military Communities
- Agency/Certification Specific Testing Information
- Contact Pearson VUE
RECERTIFICATION
CompTIA Cybersecurity Analyst (CySA+)
Renewal Period: 3 years
Additional considerations for the CompTIA Cybersecurity Analyst (CySA+) include:
- Candidate recommended to have Network+, Security+, or equivalent knowledge and/or a minimum of four years of hands-on information security or related experience.