CompTIA CySA+ · CS0-003

Learn to read the queue
before it reads you.

A CySA+ exam is really a test of judgment under a full ticket queue: which alert is real, which vulnerability matters today, and what you tell the room after. Vega Institute trains that judgment, not just the vocabulary.

85 questions · 165 min · pass at 750/900 DoD 8140 approved Vendor-neutral, tool-agnostic
INCIDENT QUEUE — SOC-01
6 open
    Simulated queue — this is the workflow you'll be trained on
    $90K–$115K
    typical US SOC analyst salary band
    40%+
    of senior cybersecurity postings prefer or require it
    4
    domains — operations, vuln management, IR, reporting
    Dec 22
    2026 — last day to sit CS0-003
    Who this is for

    Built for people already looking at logs, not people starting from zero.

    CySA+ sits above Security+ and below CASP+. It assumes you know what a firewall is and asks whether you can act on what it's telling you.

    01

    Tier 1 → Tier 2 SOC analysts

    You're triaging alerts today and want the analytical depth — correlation, prioritization, escalation — to move up the bench.

    02

    IT and helpdesk moving into security

    You have Network+ or Security+ and hands-on IT time, and you're ready to specialize in detection and response instead of general support.

    03

    Vulnerability and compliance analysts

    You already run scans or manage findings, and need the framework to prioritize by real risk instead of raw CVSS score.

    Exam blueprint

    Four domains, weighted exactly how CompTIA weights them.

    We build study time to match the exam, not an even split. Security Operations carries a third of your score — it gets a third of your hours.

    1. Security operations33%
    SIEM & log correlation SOAR playbooks EDR / XDR Network monitoring Threat intel lifecycle
    2. Vulnerability management30%
    Scanning & scoping CVSS scoring CISA KEV prioritization Cloud / IoT / ICS risk Remediation planning
    3. Incident response and management20%
    MITRE ATT&CK Cyber Kill Chain Containment & eradication Digital forensics basics
    4. Reporting and communication17%
    Stakeholder reporting MTTD / MTTR metrics PCI DSS / HIPAA / GDPR context Remediation tracking
    What you'll actually be able to do

    Not flashcards. Reps on the tools and logic a SOC runs on.

    01

    Correlate across sources

    Pull the same incident out of SIEM, EDR, and firewall logs and tell one coherent story from it.

    02

    Prioritize by real risk

    Rank vulnerabilities against exploitability and business exposure, not just CVSS alone.

    03

    Map to attacker behavior

    Tag detections to MITRE ATT&CK techniques and reason about what an attacker does next.

    04

    Run the IR lifecycle

    Move an incident through containment, eradication, and recovery without missing handoffs.

    05

    Write for two audiences

    Explain the same finding to an engineer and to a non-technical stakeholder without losing accuracy.

    06

    Read specialized environments

    Extend the same analytical model to cloud, container, and IoT/ICS assets.

    07

    Handle performance-based Qs

    Drill the simulation-style exam items, not just multiple choice, under a timer.

    08

    Track remediation to close

    Follow a finding through a ticketing/GRC workflow until it's actually resolved, not just reported.

    Curriculum

    Modules mapped straight to the four domains above.

    Pick a domain to see what's inside it. Every module ends in a scenario, not a definition to memorize.

    01
    Reading a SIEM at speed

    Query, filter, and correlate log sources under time pressure.

    02
    SOAR and automated response

    When to automate a playbook and when a human needs to decide.

    03
    Endpoint detection deep dive

    Reading EDR/XDR telemetry to separate noise from intrusion.

    04
    Threat intelligence in practice

    Using IOCs and feeds without drowning in low-value alerts.

    05
    Network traffic analysis

    Spotting lateral movement and beaconing in packet and flow data.

    06
    Identity and access signals

    Reading auth logs for brute force, MFA fatigue, and credential misuse.

    01
    Scoping and running scans

    Choosing scan type and schedule without breaking production.

    02
    Scoring beyond CVSS

    Layering exploitability, exposure, and asset criticality into a call.

    03
    Working the CISA KEV catalog

    Prioritizing what's actively exploited over what's merely severe.

    04
    Remediation vs. mitigation

    Choosing a fix when patching isn't possible this cycle.

    05
    Cloud and container exposure

    Applying the same rigor to ephemeral and cloud-native assets.

    06
    IoT and ICS considerations

    Handling assets you often can't patch or take offline.

    01
    Attack frameworks

    MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model, applied not memorized.

    02
    The IR lifecycle

    Preparation through lessons learned, with real handoff points.

    03
    Containment strategy

    Isolating a host or segment without tipping off the attacker too early.

    04
    Evidence and chain of custody

    Forensic basics that hold up if the incident becomes a legal matter.

    05
    Eradication and recovery

    Confirming an environment is actually clean before declaring closed.

    06
    Tabletop scenario labs

    Full incident walkthroughs against realistic injects.

    01
    Vulnerability reports that get read

    Structuring findings so leadership acts instead of skims.

    02
    Incident reports and timelines

    Documenting what happened in a way that survives review.

    03
    Metrics that matter

    MTTD, MTTR, and how to present them without spin.

    04
    Compliance context

    Where PCI DSS, HIPAA, and GDPR actually touch your daily work.

    05
    Communicating to non-technical stakeholders

    The same finding, reframed for risk and budget conversations.

    06
    Remediation tracking

    Following a finding through a GRC or ticketing workflow to close.

    In-class training format

    Instructor-led, in the room, working the same queue together.

    How the classroom runs

    • Live instructor-led sessions, organized by exam domain
    • Hands-on labs on classroom workstations against real SIEM, EDR, and scan-report data
    • Group tabletop incident response scenarios, worked as a team
    • Full-length timed practice exams at 85 questions / 165 minutes
    • Direct access to the instructor for questions during and between sessions

    What you should already have

    • Security+ or equivalent working knowledge, recommended by CompTIA
    • Comfort with basic networking and OS fundamentals
    • Some hands-on IT or security exposure — this isn't a first cert
    • A laptop for lab exercises; classroom workstations are also provided

    The queue doesn't wait for you to feel ready.

    Get in front of the material now, so you've got the runway to test comfortably before CS0-003 retires.