CompTIA CySA cs0 003+objectives
CompTIA CySA cs0 003+objectives
CompTIA CySA cs0 003+objectives
Analyst (CySA+)
Certification Exam
Objectives
EXAM NUMBER: CS0-003
About the Exam
The CompTIA Cybersecurity Analyst (CySA+) certification exam will certify the successful candidate
has the knowledge and skills required to:
EXAM DEVELOPMENT
CompTIA exams result from subject matter expert workshops and industry-wide survey results
regarding the skills and knowledge required of an IT professional.
PLEASE NOTE
The lists of examples provided in bulleted format are not exhaustive lists. Other examples of
technologies, processes, or tasks pertaining to each objective may also be included on the exam,
although not listed or covered in this objectives document. CompTIA is constantly reviewing the
content of our exams and updating test questions to be sure our exams are current, and the security
of the questions is protected. When necessary, we will publish updated exams based on existing
exam objectives. Please know that all related exam preparation materials will still be valid.
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
TEST DETAILS
Required exam CS0-003
Number of questions
Types of questions Multiple-choice and performance-based
Length of test
Recommended experience 4 years of hands-on experience as an
incident response analyst or security
operations center (SOC) analyst
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
1.0 Security Operations
1.1 Explain the importance of system and network architecture
concepts in security operations.
• Log ingestion • Network architecture - Privileged access management
- Time synchronization - On-premises (PAM)
- Logging levels - Cloud - Passwordless
• Operating system (OS) concepts - Hybrid - Cloud access security broker
- Windows Registry - Network segmentation (CASB)
- System hardening - Zero trust • Encryption
- File structure - Secure access secure edge - Public key infrastructure (PKI)
o
Configuration file locations (SASE) - Secure sockets layer (SSL)
- System processes - Software-defined networking inspection
- Hardware architecture (SDN) • Sensitive data protection
• Infrastructure concepts • Identity and access management - Data loss prevention (DLP)
- Serverless - Multifactor authentication (MFA) - Personally identifiable
- Virtualization - Single sign-on (SSO) information (PII)
- Containerization - Federation - Cardholder data (CHD)
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
1.0 | Security Operations
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
1.0 | Security Operations
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
2.0 Vulnerability Management
2.1 Given a scenario, implement vulnerability scanning methods
and concepts.
• Asset discovery • Credentialed vs. non-credentialed - Payment Card Industry Data
- Map scans • Passive vs. active Security Standard (PCI DSS)
- Device fingerprinting • Static vs. dynamic - Center for Internet Security
• Special considerations - Reverse engineering (CIS) benchmarks
- Scheduling - Fuzzing - Open Web Application Security
- Operations • Critical infrastructure Project (OWASP)
- Performance - Operational technology (OT) - International Organization for
- Sensitivity levels - Industrial control systems (ICS) Standardization (ISO) 27000
- Segmentation - Supervisory control and data series
- Regulatory requirements acquisition (SCADA)
• Internal vs. external scanning • Security baseline scanning
• Agent vs. agentless • Industry frameworks
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
2.0 | Vulnerability Management
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
3.0 Incident Response and
Management
3.1 Explain concepts related to attack methodology frameworks.
• Cyber kill chain - Command and Control (C2) - Infrastructure
- Reconnaissance - Actions and objectives - Capability
- Weaponization • Diamond Model of Intrusion • MITRE ATT&CK
- Delivery Analysis • Open Source Security Testing
- Exploitation - Adversary Methodology Manual (OSS TMM)
- Installation - Victim • OWASP Testing Guide
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
4.0 Reporting and Communication
4.1 Explain the importance of vulnerability management reporting
and communication.
• Vulnerability management - Compensating controls - Proprietary systems
reporting - Awareness, education, and • Metrics and key performance
- Vulnerabilities training indicators (KPIs)
- Affected hosts - Changing business requirements - Trends
- Risk score • Inhibitors to remediation - Top 10
- Mitigation - Memorandum of understanding - Critical vulnerabilities and
- Recurrence (MOU) zero-days
- Prioritization - Service-level agreement (SLA) - SLOs
• Compliance reports - Organizational governance • Stakeholder identification
• Action plans - Business process interruption and communication
- Configuration management - Degrading functionality
- Patching - Legacy systems
CompTIA Cybersecurity Analyst (CySA+) CS0-003 Certification Exam: Exam Objectives Version 1.0
CompTIA CySA+ CS0-003 Acronym List
The following is a list of acronyms that appears on the CompTIA CySA+
CS0-003 exam. Candidates are encouraged to review the complete
list and attain a working knowledge of all listed acronyms as part of a
comprehensive exam preparation program.
Acronym Spelled Out Acronym Spelled Out
API Application Programming Interface OT Operational Technology
APT Advanced Persistent Threat OWASP Open Web Application Security Project
BC Business Continuity PAM Privileged Access Management
C2 Command and Control PCI DSS Payment Card Industry Data Security
CASB Cloud Access Security Broker Standard
CERT Computer Emergency Response Team PII Personally Identifiable Information
CHD Cardholder Data PKI Public Key Infrastructure
CIS Center for Internet Security RFI Remote File Inclusion
CSIRT Cybersecurity Incident Response Team SASE Secure Access Secure Edge
CVSS Common Vulnerability Scoring System SCADA Supervisory Control and Data Acquisition
DKIM Domain Keys Identified Mail SDLC Software Development Life Cycle
DLP Data Loss Prevention SDN Software-Defined Networking
DMARC Domain-based Message Authentication, SIEM Security Information and Event Management
Reporting, and Conformance SLA Service-Level Agreement
DNS Domain Name Service SLO Service-Level Objective
DR Disaster Recovery SOAR Security Orchestration, Automation, and
EDR Endpoint Detection and Response Response
GDB GNU Debugger SPF Sender Policy Framework
ICS Industrial Control Systems SSL Secure Sockets Layer
IoC Indicators of Compromise SSO Single Sign-On
IP Internet Protocol TCP Transmission Control Protocol
ISO International Organization for TTP Tactics, Techniques, and Procedures
Standardization XDR Extended Detection Response
JSON JavaScript Object Notation XML Extensible Markup Language
KPI Key Performance Indicator ZAP Zed Attack Proxy
LFI Local File Inclusion
MFA Multifactor Authentication
MOU Memorandum of Understanding
MSF Metasploit Framework
OpenVAS Open Vulnerability Assessment Scanner
OS Operating System
OSSTMM Open Source Security Testing
Methodology Manual
CompTIA CySA+ CS0-003 Hardware and
Software List
CompTIA has included this sample list of hardware and software to assist
candidates as they prepare for the CySA+ CS0-003 certification exam.
This list may also be helpful for training companies that wish to create a
lab component for their training offering. The bulleted lists below each
topic are sample lists and are not exhaustive.
Equipment
• Workstations (or laptop) with ability to run VM
• Firewall
• IDS/IPS
• Servers
Software
• Windows operating systems
- Commando VM
• Linux operating systems
- Kali
• Open-source UTM appliance
• Metasploitable
• SIEM
- Greylog
- ELK
- Splunk
• TCPDump
• Wireshark
• Vulnerability scanner (i.e., OpenVAS)
• Nessus
• Access to cloud instances
- Azure
- AWS
- GCP
© 2022 CompTIA, Inc., used under license by CompTIA, Inc. All rights reserved. All certification programs and education related to such
programs are operated exclusively by CompTIA, Inc. CompTIA is a registered trademark of CompTIA, Inc. in the U.S. and internationally.
Other brands and company names mentioned herein may be trademarks or service marks of CompTIA, Inc. or of their respective owners.
Reproduction or dissemination prohibited without the written consent of CompTIA, Inc. Printed in the U.S. 09804-Jul2022