The CompTIA CySA+ (Cybersecurity Analyst+) is an intermediate, hands-on certification that focuses on the "Blue Team" or defensive side of security. While Security+ teaches you how to build a secure environment, CySA+ teaches you how to monitor it, hunt for threats, and respond to incidents
Write your awesome label here.
CySA+ Exam Domains
Domain Weight Key Content Areas
1. Security Operations 33% Log ingestion, analyzing network/host/application telemetry, and utilizing SIEM/SOAR tools for monitoring.
2. Vulnerability Management 30% Scanning, analyzing output from tools like Nessus/OpenVAS, and prioritizing remediation based on CVSS scores.
3. Incident Response & Management 20% The IR lifecycle (Preparation through Lessons Learned), digital forensics basics, and using frameworks like MITRE ATT&CK.
4. Reporting & Communication 17% Translating technical findings into actionable reports for stakeholders and ensuring compliance with regulatory standards.