IT Practice Exams

CS0-004 · Security Operations · Updated July 26, 2026

CompTIA CySA+ (CS0-003) Study Guide: Format, Domains, Cost, and How to Pass

CompTIA CySA+ (Cybersecurity Analyst+, exam code CS0-003) is an intermediate, vendor-neutral certification that validates you can do security operations work: read logs, triage vulnerabilities, run incident response, and communicate findings. The exam allows a maximum of 85 questions in 165 minutes, requires 750 on a 900-point scale to pass, and costs $439 per voucher. One thing to know before you build a study plan: CS0-003 retires for English-language testing on December 22, 2026, so the timeline below assumes you schedule with that deadline in mind.

What CySA+ is — and who it’s for

Where Security+ certifies that you understand security concepts, CySA+ certifies that you can apply them as a working analyst. The exam hands you firewall logs, vulnerability scan output, email headers, and packet captures, and expects you to extract the indicator, judge the severity, and choose the next action. CompTIA positions it for security analysts, security operations center (SOC) analysts, threat hunters, and vulnerability management staff with roughly three to four years of hands-on security experience — though plenty of candidates pass earlier by drilling the analysis skills deliberately.

CySA+ sits between Security+ and the advanced SecurityX (formerly CASP+) certification in CompTIA’s cybersecurity pathway. It is also approved under DoD 8140 for several cyber workforce roles, which is why it shows up in so many U.S. government and contractor job requirements. There is no mandatory prerequisite: Security+ and Network+ knowledge is recommended, not required, so you can sit CySA+ directly if your experience supports it.

Two question styles appear on the exam: standard multiple-choice questions and performance-based questions (PBQs). PBQs simulate analyst tasks — parsing a log excerpt for the malicious line, matching indicators to attack types, ordering remediation steps. They usually arrive at the front of the exam and are worth more than one point each, which is why time strategy (covered below) treats them separately.

CS0-003 exam format at a glance

DetailCS0-003
Question countMaximum of 85
Question typesMultiple-choice and performance-based (PBQ)
Time limit165 minutes
Passing score750 on a scale of 100–900
Voucher price$439 (USD)
DeliveryPearson VUE test center or OnVUE online proctoring
Recommended background3–4 years security experience; Network+/Security+ level knowledge
English retirement dateDecember 22, 2026

That works out to just under two minutes per question if the exam serves you all 85 — comfortable for multiple-choice, tight if you let a PBQ eat fifteen minutes. Note the voucher price: CompTIA raised CySA+ pricing to $439 in its May 2026 price change, so older guides quoting a lower figure are out of date.

Important: CS0-003 retires December 22, 2026

Plan around this date. CompTIA launched the successor exam, CySA+ V4 (CS0-004), on June 23, 2026, and the two versions are overlapping only briefly:

  • December 22, 2026 — last day to take CS0-003 in English.
  • March 23, 2027 — last day to take CS0-003 in other languages.
  • After retirement — CS0-004 becomes the only CySA+ exam available.

What this means practically:

  1. If you’re studying for CS0-003 now, schedule your exam date early. Test-center seats and OnVUE slots get scarce near retirement deadlines as other candidates race the same clock. Book the appointment first and let it anchor your study plan — an unscheduled exam has a way of staying unscheduled.
  2. Leave retake room. If your exam date is in December, a failed first attempt leaves you almost no runway to retake CS0-003 before the English cutoff. Aim to test by late October or November so one retake still fits.
  3. Your certification does not expire with the exam. Passing CS0-003 before retirement grants the same three-year CySA+ certification, renewable through continuing education (CEUs), exactly as a CS0-004 pass would. Employers see “CySA+,” not the exam code.
  4. If you’re starting from zero in late 2026, weigh starting directly on CS0-004 instead — study materials for a retiring exam stop being useful the day it retires, and a failed December attempt would force you to restart against new objectives anyway.

This guide covers CS0-003. The analyst skills transfer heavily to CS0-004, but the objectives, domain structure, and question pool are distinct.

The four CS0-003 domains

CS0-003 organizes its objectives into four domains. The weights below are the official distribution of exam content:

DomainWeight
Security Operations33%
Vulnerability Management30%
Incident Response and Management20%
Reporting and Communication17%

Two domains — Security Operations and Vulnerability Management — carry 63% of the exam between them. Weight your study time the same way.

Domain 1: Security Operations (33%)

The largest domain covers the daily work of a SOC: system and network architecture concepts (logging levels, time synchronization, identity, network segmentation), analyzing potentially malicious activity, tooling (SIEM, EDR, SOAR), and the efficiency work that keeps a SOC from drowning — automation, orchestration, and process improvement.

Threat intelligence is the intellectual core of this domain. You need the full threat intelligence lifecycle — requirements through dissemination and feedback — plus how finished intel turns into detections and tasks threat hunts. Expect questions on evaluating intel quality using confidence levels and the Admiralty system, on choosing among intelligence sources — OSINT, closed-source feeds, ISACs, and internal telemetry, and on the riskier collection disciplines: dark web monitoring and HUMINT, where operational stealth and legal guardrails matter as much as the data collected.

On the automation side, know how a security orchestration, automation, and response (SOAR) platform ingests multiple feeds and what to do when they disagree — enrichment, deduplication, and feed-conflict resolution is a recurring scenario. Insider risk rounds out the domain: distinguishing malicious from unintentional insider threats and the DLP controls that catch data leaving, and protecting regulated data analysts encounter in their own tooling — see tokenization and PAN exposure in logs for the cardholder-data angle.

Domain 2: Vulnerability Management (30%)

The second-largest domain covers the vulnerability lifecycle: scanning methods and configuration (credentialed vs. non-credentialed, agent vs. agentless, active vs. passive), interpreting scanner output, prioritization, and response.

The skill the exam drills hardest is reading results critically. You must recognize false positives and false negatives in scan output and prioritize by actual risk — CVSS score alone is never the full answer; asset criticality, exploitability, and exposure all modify it. Expect output-interpretation questions where the scanner flags something the system’s compensating configuration already mitigates.

Compliance scanning gets specific treatment through the Payment Card Industry Data Security Standard (PCI DSS), the exam’s favorite regulatory example. Know how quarterly ASV scans work, what a failing result means, and how rescans prove remediation. Know what happens when a required control can’t be implemented as written — compensating controls, what you must demonstrate, and how the Attestation of Compliance reflects them.

Domain 3: Incident Response and Management (20%)

This domain follows the incident response lifecycle — preparation; detection and analysis; containment, eradication, and recovery; post-incident activity — with emphasis on the analyst’s decisions inside each phase. Attack methodology frameworks (the Cyber Kill Chain, MITRE ATT&CK, the Diamond Model) appear here as tools for mapping observed activity to attacker progress and predicting the next move.

Expect scenarios that test phase discrimination (is disabling the account containment or eradication?), evidence handling and chain of custody basics, and indicator-of-compromise analysis that leans on the same log-reading skills as Domain 1. Post-incident questions focus on lessons learned, root cause analysis, and feeding findings back into detections and controls — the exam consistently rewards answers that close the loop rather than end at “incident resolved.”

Domain 4: Reporting and Communication (17%)

The smallest domain, and the one experienced technical candidates most often underestimate. It covers vulnerability reporting and incident reporting as distinct disciplines: what goes in each report, which metrics matter (mean time to detect, mean time to remediate, recurrence), and — the exam’s obsession — matching content and detail level to the audience. Executives get risk and business impact; technical teams get affected hosts and remediation steps; regulators get what the regulation requires.

PCI DSS returns here from the communication angle: structuring vulnerability compliance reports for PCI — CDE scope, audiences, and remediation plans, and knowing who a merchant must notify after a cardholder data breach — acquiring banks and card brands, not just customers. Stakeholder-identification questions (“who must be informed, in what order?”) are reliable exam material.

How CySA+ differs from Security+ — and why that changes how you study

Most CySA+ candidates arrive from Security+, and the single biggest preparation mistake is studying the same way. Security+ is primarily a knowledge exam: it asks what a control is, what an attack does, which concept a definition matches. CySA+ is an application exam: it shows you an artifact and asks what it means. A Security+ question might ask which protocol DNS tunneling abuses; the CySA+ version hands you a DNS log excerpt with abnormally long TXT-record queries to a single domain and asks what you’re looking at and what to do next.

That shift has three concrete consequences for your preparation:

  1. Flashcard knowledge is necessary but not sufficient. You still need the vocabulary — every acronym, framework, and control type — but memorization gets you to maybe half the exam. The other half is pattern recognition, and pattern recognition only comes from reps against realistic scenarios and output samples.
  2. Exhibits are the exam. Practice reading firewall logs, web server logs, email headers, Nmap and vulnerability scanner output, and packet capture summaries until the anomalous line jumps out at you before you’ve consciously parsed the rest. On exam day you will not have time to read every exhibit line by line; you need trained eyes.
  3. Judgment questions have a house style. CySA+ consistently rewards proportionate, evidence-driven responses: validate before acting, contain before eradicating, communicate to the right stakeholder at the right time. Answers that are technically powerful but disproportionate — reimage everything, block the entire subnet, notify the public immediately — are usually distractors.

Candidates who fail CS0-003 on a first attempt overwhelmingly report the same two causes: time pressure from PBQs they didn’t rehearse, and scenario questions where they knew every term but hadn’t practiced choosing between two defensible actions. Both are fixable in study weeks 5 and 6 — but only if your practice material makes you exercise the judgment, not just recall the definitions.

Registering for the exam

Registration runs through CompTIA and Pearson VUE:

  1. Buy a voucher — $439 from the CompTIA store (the price set in the May 2026 increase). Bundles that add a retake voucher or training materials cost more but are worth pricing out if you’re not confident of a first-attempt pass, especially with the retirement clock limiting retake windows.
  2. Choose delivery — Pearson VUE test center or OnVUE online proctoring. Test centers offer fewer variables: no webcam room scan, no environmental tech risk. OnVUE trades that for convenience, but requires a private room, a clean desk, a reliable connection, and a system check you should run days in advance — not exam morning.
  3. Schedule — create or sign in to your Pearson VUE account, select CS0-003, pick a date. Given the retirement deadline, schedule as early as your preparation honestly allows.
  4. Exam day ID — you need a valid government-issued photo ID matching your registration name exactly.

A 6-week study plan for CS0-003

This plan assumes roughly 10–12 hours per week and Security+-level baseline knowledge. Compress to four weeks if you work in a SOC today; stretch to eight or ten if you’re pivoting from general IT.

Week 1 — Security Operations, part 1. Architecture and log fundamentals: log ingestion, time sync, network and identity concepts. Then threat intelligence end to end — lifecycle phases, source types, confidence rating, and how intel feeds detection and hunting. Read the Domain 1 spokes linked above as you go. Finish the week with a 25-question domain quiz to baseline yourself.

Week 2 — Security Operations, part 2. Malicious activity analysis: work through log excerpts, email headers, and command-line artifacts until identifying the anomalous line feels mechanical. Cover SIEM/EDR/SOAR tooling concepts, automation, and insider threat/DLP. This is the domain where hands-on reps pay off most — analyze something real (home lab traffic, public sample logs) every session.

Week 3 — Vulnerability Management. Scan types and configuration, then output interpretation: false positives, prioritization, CVSS and its limits. Drill the PCI DSS scanning content — ASV scans, compensating controls. Take a full-domain quiz; vulnerability questions are heavily scenario-based, so grade yourself on reasoning, not just correctness.

Week 4 — Incident Response and Management. The IR lifecycle phase by phase, attack frameworks (ATT&CK, Kill Chain, Diamond Model), evidence handling. Practice phase-discrimination questions specifically — they’re the domain’s signature trap. Map three or four public breach writeups to the frameworks as an exercise.

Week 5 — Reporting and Communication + weak areas. Report types, metrics and KPIs, audience matching, and the PCI reporting/notification material. Then return to whichever earlier domain scored worst and rework it. Take your first full-length timed practice exam at the end of this week and review every miss to the objective level.

Week 6 — Full-exam simulation and polish. Two or three full timed practice exams on alternating days, deep review between. You’re calibrating pace (PBQ time budget especially) as much as knowledge. Stop learning new material two days out; final day is light review of your notes and the domain weight table, then rest.

Throughout: keep a running miss log — objective number, what you picked, why the right answer is right. Reviewing that log in week 6 is worth more than any new material.

Exam-day tips

  • Flag and move on PBQs. They cluster at the start and can consume your buffer. Give each a fair attempt, but if one balloons past several minutes, flag it and return after the multiple-choice section — unanswered scores zero, but so does a half-finished exam.
  • Answer everything. No penalty for wrong answers; never leave a blank.
  • Read stems for the qualifier. CySA+ loves best, first, most likely, and immediate. Several options are often defensible; the qualifier picks the winner. “First” usually rewards the analysis or containment step, not the eventual fix.
  • Think like an analyst, not an engineer. When options split between “investigate/validate/contain” and “rebuild/re-architect,” the analyst answer — scoped, evidence-driven, reversible — usually wins.
  • Use elimination on log questions. Two options typically fail on a plain factual mismatch with the exhibit (wrong port, wrong host, wrong direction). Cut those first, then discriminate between the survivors.
  • OnVUE takers: complete check-in early, clear the desk completely, and remember you can’t take notes on paper — use the provided digital whiteboard.
  • Watch the clock at halfway. At ~82 minutes you should be near question 45 if the exam served you the full 85. Adjust pace, don’t panic.

Quick reference

  • CySA+ CS0-003: intermediate analyst cert; maximum of 85 questions, 165 minutes, passing score 750/900.
  • Voucher: $439 after the May 2026 CompTIA price change; delivered at Pearson VUE test centers or via OnVUE online proctoring.
  • Domains: Security Operations 33%, Vulnerability Management 30%, Incident Response and Management 20%, Reporting and Communication 17%.
  • Retirement: CS0-003 leaves English testing December 22, 2026 (other languages March 23, 2027); successor CS0-004 launched June 23, 2026. Schedule with retake room — test by late October/November if you can.
  • Certification earned on CS0-003 remains a full three-year CySA+ credential, renewable via CEUs.
  • 63% of the exam is Security Operations + Vulnerability Management — weight study time accordingly.
  • PBQs come first and are worth more than one point; budget time for them deliberately and flag rather than stall.
  • The exam rewards analyst reasoning: validate evidence, act on the qualifier in the stem, close the loop after incidents.
Choose your exam → Lifetime access
from $59, once