CS0-003 Available
CompTIA CySA+ quest path
Threat detection, vulnerability management, security operations, and analyst workflow prep.
Knowledge map
Practice by objective
Reviewed 2026-09-08. Topic labels summarize the linked study material; objective numbers identify the exam scope.
1.0 Security Operations5 objectives101 questions
Log ingestion and time synchronization; Operating system telemetry; Infrastructure and network architecture; Identity and access management; Encryption and sensitive data protection
Network indicators; Host indicators; Application and identity indicators
Packet, endpoint, and SIEM tools; Email and file analysis; User behavior and anomalous activity; Scripting and structured data
Threat actors and TTPs; Intelligence confidence and sources; Intelligence sharing; Threat hunting and deception
Standardization and orchestration; Tool integration and visibility
2.0 Vulnerability Management5 objectives92 questions
Scanning methods and safety; Scan scope, vantage, and authentication; Application and baseline scanning; Frameworks and scanner content
Web assessment output; Network and host assessment output; Cloud and human assessment output
CVSS interpretation; Validation and result quality; Contextual prioritization
Access and injection controls; Request, file, and execution controls; Overflow and platform controls; Design, component, and data controls
Risk treatment and control selection; Patch, configuration, and exceptions; Secure development and attack surface
3.0 Incident Response and Management3 objectives61 questions
Attack methodology frameworks
Detection and analysis; Containment, eradication, and recovery; Forensics and evidence handling
Preparation and post-incident improvement
4.0 Reporting and Communication2 objectives51 questions
Vulnerability reports and action plans; Vulnerability metrics and stakeholders
Incident metrics and lessons learned; Incident reports and communication