Cyber Security Category

CompTIA Cybersecurity Analyst (CySA+)

  • Length 5 days
  • Version CS0-004
Course overview
View dates &
book now

Why study this course

CompTIA Cybersecurity Analyst (CySA+) is a cybersecurity certification that validates your ability to detect, analyse, and respond to threats in security operations and vulnerability management roles. It focuses on incident detection, response, and continuous monitoring in modern environments, while managing vulnerabilities and effectively communicating critical risks.

CySA+ V4 reflects how cybersecurity roles operate today by expanding coverage of security operations, cloud and hybrid environments, and identity-based threats. Compared to V3, it places greater emphasis on vulnerability prioritisation, risk-based decision-making, and applied, real-world skills across detection, response, and communication. The new version also introduces concepts related to AI in security operations, helping you prepare for modern cybersecurity challenges.

The CompTIA CySA+ CS0-004 V4 certification exam will certify the successful candidate has the knowledge and skills required to:

  • Understand and perform incident response and vulnerability management processes.

  • Detect and analyse indicators of malicious activity in support of security operations.

  • Use appropriate tools, methods, and frameworks to prioritise and manage vulnerabilities and respond to incidents.

  • Understand reporting and communication concepts related to vulnerability management and incident response activities.

Please note: The exam is not included in the course fee but can be purchased separately. Please contact us for a quote.

Aligns to certification

Request Course Information


What you’ll learn

  • Identify and investigate suspicious activity across networks, endpoints, and cloud environments to uncover potential security threats.

  • Monitor and analyse data using industry-standard tools such as SIEM and EDR platforms.

  • Identify, prioritise, and mitigate vulnerabilities using risk-based approaches.

  • Investigate and respond to security incidents using structured processes and real-world techniques.

  • Clearly communicate security findings and risks to stakeholders through reports and dashboards.

  • Apply security practices across cloud and hybrid environments while supporting efficient and effective operations.


CompTIA Authorized Partner logo - CAPP Gold Partner

CompTIA at Lumify Work

CompTIA is the voice of the world’s information technology (IT) industry. A non-profit association, CompTIA offers IT professionals vendor neutral, industry-leading IT certifications. Lumify Work is proud to be a CAPP Gold Partner – offering A+, Network+, Security+, CySA+, Pentest+, and more.


Who is the course for?

CySA+ is a strong fit if you are working in or planning to move into cybersecurity roles focused on threat detection, vulnerability management, and incident response. It aligns well with roles such as cybersecurity analyst, SOC analyst, threat intelligence analyst, vulnerability analyst, and incident responder.


Course subjects

Domain 1 - Security Operations

  • Explain system and network architecture concepts in security operations:

    Security architecture components, identity concepts, and logging practices that support secure environments.

  • Analyse indicators of potential malicious activity:

    Suspicious activity across networks, endpoints, cloud, and identity systems.

  • Use tools to determine malicious activity:

    SIEM, EDR, packet analysis tools, and threat intelligence platforms.

  • Explain threat intelligence and threat-hunting concepts:

    Frameworks, data sources, and methods used to identify and investigate threats.

  • Describe efficiency and process improvement in security operations:

    Automation, workflows, and processes used to improve operational efficiency.

  • Summarise concepts related to the use of AI in security operations:

    Use cases, risks, and governance considerations.

Domain 2 - Vulnerability Management

  • Implement the appropriate vulnerability scanning method:

    Tools and techniques used to identify vulnerabilities across systems, networks, and applications.

  • Analyse output from vulnerability assessment tools:

    Vulnerabilities, findings, and security gaps identified through scan results.

  • Prioritise and mitigate vulnerabilities:

    Risk-based approaches using scoring systems, threat intelligence, and business context.

  • Explain concepts related to control types, risks, and vulnerability management:

    Controls, policies, and compliance practices used to manage risk.

Domain 3 - Incident Response and Management

  • Summarise concepts related to attack methodology frameworks:

    Models such as MITRE ATT&CK and the Cyber Kill Chain.

  • Outline the incident response process:

    Phases including preparation, detection, analysis, containment, eradication, and recovery.

  • Implement incident response techniques:

    Triage, evidence handling, escalation, remediation, and root cause identification.

Domain 4 - Reporting and Communication

  • Explain vulnerability management reporting and communication:

    Reports, dashboards, and communication activities used to present findings and support escalation during security events.

  • Describe security operations, incident response reporting, and communication:

    Incident documentation, post-incident reviews, and metrics such as detection time, response time, and remediation effectiveness.


Prerequisites

Network+, Security+ or equivalent knowledge. Minimum of 4 years of hands-on experience as an incident response analyst or security operations center (SOC) analyst, or equivalent experience. 


Lumify Work is proud to be Cyber Security Training Business of the Year

ACA26 Winner Cyber Training Business of the Year 1


Terms & Conditions

The supply of this course by Lumify Work is governed by the booking terms and conditions. Please read the terms and conditions carefully before enrolling in this course, as enrolment in the course is conditional on acceptance of these terms and conditions.


Request Course Information

Select and book a course

September
October
November
December
January

Can't find a date you like?

Contact sales



Offers

Cyber Analyst and Incident Professional Bundle
This bundle combines two highly recognised certifications: CompTIA Cybersecurity Analyst+ (CySA+) and EC-Council Certified Incident Handler (ECIH). Professionals will be provided with instructor-led training and exam vouchers for both courses.