CompTIA CySA+ (CS0-004) exam objectives
CompTIA publishes 4 exam domains with official weightings. The weight tells you where your marks come from, so your study time should roughly follow it.
CS0-004Advanced
1. Security Operations
34%- Log, endpoint and network analysis: reading the evidence, not reciting tool names
- Threat hunting and threat intelligence: hypotheses, IoCs, TTPs, MITRE ATT&CK mapping
- Detection engineering: tuning rules, cutting false positives, correlation in a SIEM
- Efficiency and automation: scripting, SOAR playbooks, enrichment pipelines
2. Vulnerability Management
26%- Scan configuration and execution: credentialed vs uncredentialed, scope, scheduling
- Analysing output and validating findings: confirming true positives, discarding noise
- Prioritisation beyond raw CVSS: exploitability, asset value, exposure, compensating controls
- Controls, remediation workflows and verifying the fix actually landed
3. Incident Response and Management
24%- Attack methodology frameworks and where an incident sits in the kill chain
- The response lifecycle: detection, containment, eradication, recovery
- Evidence handling: chain of custody, acquisition order, forensic soundness
- Post-incident activity: root cause, lessons learned, control improvement
4. Reporting and Communication
16%- Vulnerability reporting for technical and non-technical audiences
- Metrics and KPIs that mean something: MTTD, MTTR, SLA adherence, recurrence
- Incident reporting, escalation paths and regulatory notification under uncertainty
- Stakeholder communication during an active incident, including who decides what
Our practice exam spreads its questions across these exact domains at these weightings, so your score in each one tells you precisely where you stand.
Practice these objectives free →