Course Information
What You Will Learn
Course Curriculum
– Cybersecurity Analysts
– Cybersecurity Roles and Responsibilities
– Frameworks and Security Controls
– Risk Evaluation
– Penetration Testing Processes
– Reconnaissance Techniques
– The Kill Chain
– Open Source Intelligence
– Social Engineering
– Topology Discovery
– Service Discovery
– OS Fingerprinting
– Security Appliances
– Configuring Firewalls
– Intrusion Detection and Prevention
– Configuring IDS
– Malware Threats
– Configuring Anti-Virus Software
– Sysinternals
– Enhanced Mitigation Experience Toolkit
– Logging and Analysis
– Packet Capture
– Packet Capture and Monitoring Tools
– Log Review and SIEM
– SIEM Data Outputs
– SIEM Data Analysis
– Point-in-time Data Analysis
– Managing Vulnerabilities
– Vulnerability Management Requirements
– Asset Inventory
– Data Classification
– Vulnerability Management Processes
– Vulnerability Scanners
– Microsoft Baseline Security Analyzer
– Vulnerability Feeds and SCAP
– Configuring Vulnerability Scans
– Vulnerability Scanning Criteria
– Exploit Frameworks
– Remediating Vulnerabilities
– Analyzing Vulnerability Scans
– Remediation and Change Control
– Remediating Host Vulnerabilities
– Remediating Network Vulnerabilities
– Remediating Virtual Infrastructure Vulnerabilities
– Secure Software Development
– Software Development Life Cycle
– Software Vulnerabilities
– Software Security Testing
– Interception Proxies
– Web Application Firewalls –
Source Authenticity
– Reverse Engineering
– Incident Response
– Incident Response Processes
– Threat Classification
– Incident Severity and Prioritization
– Types of Data
– Forensics Tools
– Digital Forensics Investigations
– Documentation and Forms
– Digital Forensics Crime Scenes
– Digital Forensics Kits
– Image Acquisition
– Password Cracking
– Analysis Utilities
– Incident Analysis and Recovery
– Analysis and Recovery Frameworks
– Analyzing Network Symptoms
– Analyzing Host Symptoms
– Analyzing Data Exfiltration
– Analyzing Application Symptoms
– Using Sysinternals
– Containment, Eradication, and Validation Techniques
– Corrective Actions
– Secure Network Design
– Network Segmentation
– Blackholes, Sinkholes, and Honeypots
– System Hardening
– Group Policies and MAC
– Endpoint Security
– Managing Identities and Access
– Network Access Control
– Identity Management
– Identity Security Issues
– Identity Repositories
– Context-based Authentication
– Single Sign-On and Federation
– Exploiting Identities
– Exploiting Web Browsers and Applications
– Security Frameworks and Policies
– Frameworks and Compliance
– Reviewing Security Architecture
– Procedures and Compensating Controls
– Verifications and Quality Control
– Security Policies and Procedures
– Personnel Policies and Training
Get the Full Syllabus as a PDF
Curriculum, exam format & everything included — sent straight to your inbox.
All You Need to Know
IT professionals and information security experts, already with professional experience, who intend to obtain the CompTIA CySA+ certification
There are no specific prerequisites, but it is preferable to have obtained the CompTIA Network+ and CompTIA Security+ certifications.
The course includes:
– Course slides
– Official CompTIA guide in digital format in English
– Online database with official CompTIA exam practice exercises
– Rich set of online laboratories on the CompTIA platform functional to the practical application of the concepts
Exam can be purchased in addition to the participation fee, for those interested in certification in addition to learning the concepts and practical techniques
Upcoming Certified Cybersecurity Analyst Batches
Pick a start date that works for you — every cohort includes the same official courseware, live instructor access and exam voucher.
| Start | End | Status | Study Mode | |
|---|---|---|---|---|
| 19/10/2026 | 23/10/2026 | Open | Online Live | |
| 16/11/2026 | 20/11/2026 | Open | Online Live | |
| 07/12/2026 | 11/12/2026 | Open | Online Live | |
| 25/01/2027 | 29/01/2027 | Open | Online Live | |
| 01/09/2026 | 31/03/2027 | Open | Self-Paced |
No batches match your filters — try widening the date range.
Career Opportunities After CompTIA CySA+ Certification
Analyses logs, network traffic and threat intelligence to identify risks, and recommends controls to strengthen security posture. UK salary: ITJobsWatch permanent vacancies, 6 months to Sep 2026 (10th pct / median / 90th pct).
Hiring Companies
Average Salary
Monitors security alerts, investigates suspicious activity and escalates confirmed incidents. 90th percentile not published for this period. UK salary: ITJobsWatch permanent vacancies, 6 months to Sep 2026 (10th pct / median / 90th pct).
Hiring Companies
Average Salary
Assesses risks, supports incident response and helps the organisation meet security policies and compliance requirements. UK salary: ITJobsWatch permanent vacancies, 6 months to Sep 2026 (10th pct / median / 90th pct).
Hiring Companies
Average Salary
Runs and interprets vulnerability scans, prioritises remediation by risk and tracks fixes with IT teams. Small sample (20 vacancies). UK salary: ITJobsWatch permanent vacancies, 6 months to Sep 2026 (10th pct / median / 90th pct).
Hiring Companies
Average Salary
Frequently Asked Questions
CompTIA Cybersecurity Analyst (CySA+) is an intermediate cybersecurity certification that validates your ability to detect, analyse and respond to threats. It focuses on security operations, vulnerability management, incident response, and reporting and communication — the day-to-day work of a SOC or security analyst. It is a common next step after Security+.
The price depends on the package you choose. For CompTIA CySA+, Profice offers Online Live instructor-led training (Live course, or Live course + exam) and Self-Paced E-Learning + Exam. The "+ exam" packages include the official CompTIA exam voucher, official courseware, hands-on labs, a certificate and lifetime support. Current prices for your region are shown in the pricing panel on this page (prices exclude VAT).
CySA+ is more demanding than Security+ because it tests hands-on analysis rather than concepts alone. The current exam, CS0-004 (launched 23 June 2026), has up to 85 questions, a 165-minute time limit and a passing score of 750 on a 100–900 scale. CompTIA lists 22 December 2026 as the retirement date for the English CS0-003 exam.
No — there are no mandatory prerequisites. However, having CompTIA Network+ and Security+ (or equivalent knowledge) is recommended, along with practical experience in a security or IT operations role. The course is aimed at IT and information security professionals who already have some professional experience.
CySA+ is aligned with blue-team roles such as SOC Analyst, Security Analyst, Incident Response Analyst and Vulnerability Management Analyst. It suits professionals moving from general IT or Security+-level work into dedicated security operations. Job outcomes also depend on your experience, skills and local job market.