CompTIA CySA+

CompTIA

Complete guide to passing the CompTIA CySA+ exam on your first attempt.

HardMedium-High Search Volume
Key Information at a Glance
Cost

$392

Pass Rate

~70%

Validity

3 years

Region

Global

Provider

CompTIA

Salary Impact

$75k-$110k

Are you ready for CompTIA CySA+?

Loading quiz...

Complete Overview

CompTIA CySA+ is an intermediate, vendor-neutral cybersecurity analyst certification that tests whether you can detect, analyze, and respond to threats inside a security operations centre. It is written for SOC analysts, vulnerability analysts, threat intelligence analysts, and incident responders with roughly four years of hands-on experience, and CompTIA lists the United States retail price of the current V4 voucher at $425.

Two exam versions are live at the same time. V3 carries the exam code CS0-003 and launched on 6 June 2023. V4 carries the exam code CS0-004 and launched on 23 June 2026. CompTIA has published the retirement schedule for the older version: English learning products retire on 22 November 2026, the English CS0-003 exam retires on 22 December 2026, and the Japanese, Portuguese, and Spanish translations retire on 23 March 2027. If you are booking a test date after December 2026, CS0-004 is the only English option.

Both versions share the same mechanics. You get a maximum of 85 items, 165 minutes, and a mix of multiple-choice and performance-based questions. Scoring runs on a 100 to 900 scale and 750 passes. The performance-based questions are the part candidates underestimate: CompTIA describes them as tasks such as analyzing SIEM alerts, reviewing logs and security events, investigating indicators of compromise, prioritizing vulnerabilities, and recommending remediation. They are not multiple choice with extra steps.

The V4 blueprint splits into four domains: Security Operations at 34 percent, Vulnerability Management at 26 percent, Incident Response and Management at 24 percent, and Reporting and Communication at 16 percent. Compared to V3, CompTIA added dedicated coverage of AI use cases and AI risk in the SOC, expanded Zero Trust Network Access and Secure Access Service Edge, brought in Exploit Prediction Scoring System based vulnerability prioritization, and deepened software bill of materials and supply chain content. V3 weighted Security Operations at 33 percent and Vulnerability Management at 30 percent, so the shift moves several points from vulnerability work into incident response.

CompTIA recommends Network+ and Security+ or equivalent knowledge before attempting CySA+, along with about four years in a SOC analyst, incident response, or vulnerability management role. Nothing is enforced. Anyone can buy a voucher and sit the exam. CompTIA estimates most candidates need 30 to 55 hours of study and practice.

The certification is valid for three years and renews through the CompTIA Continuing Education program, which requires 60 CEUs for CySA+ or a single qualifying activity such as passing a higher-level CompTIA exam. CySA+ is approved under United States Department of Defense Directive 8140.03M and the program is ISO 17024 compliant, which is why it appears on so many federal and defence contractor job requisitions.

Why Get CompTIA CySA+ Certified?

CySA+ is approved by the United States Department of Defense under Directive 8140.03M, and CompTIA maps CS0-003 to ten DCWF work roles including cyber defense analyst, cyber defense incident responder, and vulnerability assessment analyst. That mapping is what puts the certification on federal and cleared contractor job postings.

Earning CySA+ automatically renews eligible lower-level CompTIA certifications, including Security+ and Network+, so one $425 exam clears three years of renewal obligations on multiple credentials at once.

The exam includes performance-based questions rather than only multiple choice. CompTIA names the tasks directly: analyzing SIEM alerts, reviewing logs and security events, investigating indicators of compromise, prioritizing vulnerabilities, and recommending remediation.

The salary band associated with CySA+ holders runs $75k to $110k, which places it above entry-level Security+ roles and below the architect-level bands attached to SecurityX.

V4 adds four content areas that map directly to work most SOCs started doing in the last two years: AI use cases and AI risk in security operations, ZTNA and SASE, EPSS-based vulnerability prioritization, and SBOM and software supply chain risk.

CySA+ sits between Security+ and SecurityX in CompTIA's published cybersecurity pathway, which runs Network+, then Security+, then CySA+, then advanced specializations.

Renewal is cheap relative to the exam. Sixty CEUs plus the $150 three-year CE fee keeps the credential live, and the fee is waived entirely if you renew by earning a higher CompTIA certification instead.

Exam Format & Structure

Duration

165 minutes

Questions

Maximum of 85 questions

Passing Score

750 on a scale of 100 to 900

Question Types

  • Multiple-choice questions
  • Performance-based questions covering tasks such as SIEM alert analysis, log and event review, indicator of compromise investigation, and vulnerability prioritization

Delivery Method

Computer-based at a Pearson VUE test centre or online through Pearson OnVUE remote proctoring. CompTIA charges the same voucher price for both.

Exam Domains & Topics

Security operations
34%

The largest domain on CS0-004. It covers the architecture and logging foundations an analyst works against, how to read indicators of malicious activity across networks, endpoints, cloud, and identity systems, which tools produce which evidence, and how threat intelligence and threat hunting feed detection. V4 adds a dedicated objective on AI use cases, AI risk, and AI governance inside the SOC.

Key Topics to Master:

  • System and network architecture concepts including logging, identity, and encryption
  • Indicators of malicious activity across network, host, application, cloud, and identity telemetry
  • SIEM, EDR, XDR, and packet analysis tooling for determining malicious activity
  • Threat intelligence frameworks, data sources, confidence levels, and intelligence sharing
  • Threat hunting methodology and hypothesis-driven investigation
  • Efficiency and process improvement through automation, SOAR workflows, and tool integration
  • AI use cases in security operations, AI-related risks, and AI governance and oversight
  • Zero Trust Network Access and Secure Access Service Edge concepts
  • Email header analysis, pattern recognition, and scripting with Python and PowerShell
Vulnerability management
26%

Covers choosing and running the right scanning method, reading the output of assessment tools without drowning in false positives, and prioritizing what to fix using risk rather than raw severity. V4 expands prioritization beyond CVSS into the Exploit Prediction Scoring System and adds software bill of materials and supply chain risk content.

Key Topics to Master:

  • Asset discovery and internal versus external scanning
  • Credentialed versus non-credentialed and agent versus agentless scanning
  • Static and dynamic application security testing
  • Analyzing output from network scanners, web application scanners, and cloud infrastructure assessment tools
  • CVSS interpretation and Exploit Prediction Scoring System based prioritization
  • Validating findings, identifying false positives, and assessing exploitability
  • Software bill of materials and software supply chain risk
  • Control types, compensating controls, patching, and exception governance
  • Risk-based remediation planning and service-level objectives
Incident response and management
24%

Covers the frameworks analysts use to describe an intrusion and the process they follow to contain it. Expect questions that give you a partial timeline and ask which phase you are in or what the next action should be. V4 raised this domain from 20 percent in V3, so the weighting now rewards candidates who have actually worked an incident rather than only read about one.

Key Topics to Master:

  • MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model of intrusion analysis
  • Preparation, detection, analysis, containment, eradication, and recovery phases
  • Triage and severity classification of alerts
  • Evidence handling, chain of custody, and forensic acquisition
  • Escalation criteria and incident declaration
  • Root cause analysis and post-incident review
  • Incident response plans, playbooks, and tabletop exercises
  • Business continuity and disaster recovery interaction with incident response
Reporting and communication
16%

The smallest domain and the one technical candidates lose points on. It covers how vulnerability and incident findings get written up, which metrics stakeholders care about, and how escalation and compliance reporting work. Questions are usually scenario framed: given an audience and a finding, choose what to include or who to notify.

Key Topics to Master:

  • Vulnerability management reports, dashboards, and compliance reporting
  • Action plans and inhibitors to remediation such as MOUs, SLAs, and legacy systems
  • Metrics and KPIs including mean time to detect, mean time to respond, and remediation effectiveness
  • Stakeholder identification and audience-appropriate communication
  • Incident declaration, escalation paths, and regulatory notification
  • Lessons learned documentation and post-incident review output
  • Presenting risk to non-technical executives

Recommended Study Plan

Week 1: Blueprint mapping and baseline assessment
6-8 hours
  • 1Download the CS0-004 exam objectives PDF from the CompTIA CySA+ V4 page and build a spreadsheet with one row per objective
  • 2Take the free ten-question CompTIA CySA+ practice quiz and one full-length practice exam cold to find your weak domain
  • 3Decide between V3 and V4 based on your test date, remembering the English CS0-003 exam retires 22 December 2026
  • 4Buy the voucher or a CertMaster bundle early, since a CompTIA voucher is valid for 12 months and the expiry cannot be extended
  • 5Book a provisional test date roughly ten weeks out to force a deadline
Week 2: Architecture, logging, and identity foundations
10-12 hours
  • 1Work through the Security Operations architecture objectives in CertMaster Learn or the Sybex CySA+ study guide
  • 2Build a home lab with Security Onion or a free Splunk instance and ingest Windows Security event logs
  • 3Practise reading Windows event IDs 4624, 4625, 4688, and 4720 until you can identify the activity without lookup
  • 4Diagram how logs move from endpoint to collector to SIEM in your own environment or a lab
  • 5Review Zero Trust Network Access and SASE concepts against the CompTIA V4 objectives
Week 3: Indicators of malicious activity
10-12 hours
  • 1Study network, host, application, and identity indicators as separate lists so you can tell them apart under time pressure
  • 2Run five TryHackMe SOC Level 1 rooms focused on log analysis and network traffic
  • 3Analyze three real packet captures in Wireshark and write a two-line verdict for each
  • 4Practise email header analysis on suspicious samples, identifying SPF, DKIM, and DMARC failures
  • 5Drill VirusTotal and sandbox output interpretation
Week 4: SIEM, EDR, and detection tooling
10-12 hours
  • 1Write ten Splunk or Elastic queries that would detect brute force, lateral movement, and data staging
  • 2Complete LetsDefend or Blue Team Labs Online alert triage exercises to build speed
  • 3Study SOAR playbook design and where automation replaces analyst effort
  • 4Cover the V4 AI in security operations objective: AI use cases, AI-related risks, and AI governance
  • 5Retake a domain-level practice quiz on Security Operations and log the score
Week 5: Threat intelligence and threat hunting
8-10 hours
  • 1Map five recent adversary techniques to MITRE ATT&CK tactic and technique IDs using the ATT&CK Navigator
  • 2Compare intelligence sources by confidence level and write down when you would act on each
  • 3Practise writing a hunting hypothesis and the query that would test it
  • 4Study STIX and TAXII and how intelligence sharing communities operate
  • 5Read one recent public threat report end to end and extract the IOCs and TTPs yourself
Week 6: Vulnerability scanning methods
10-12 hours
  • 1Run credentialed and non-credentialed scans against a lab target with OpenVAS or Nessus Essentials and compare the output
  • 2Document when agent-based scanning beats agentless and why credentialed scans find more
  • 3Study scanning constraints in critical infrastructure, OT, and cloud environments
  • 4Practise reading raw scanner output and separating a real finding from a false positive
  • 5Cover SAST and DAST differences and where each fits in the SDLC
Week 7: Prioritization and mitigation
10-12 hours
  • 1Score five real CVEs by hand using the CVSS calculator, then compare against their EPSS scores
  • 2Build a prioritization exercise where CVSS and EPSS disagree and justify your ordering
  • 3Study SBOM structure and how supply chain findings enter the vulnerability queue
  • 4Review compensating controls, exceptions, maintenance windows, and remediation governance
  • 5Take a Vulnerability Management domain quiz and target anything under 80 percent
Week 8: Incident response process and frameworks
10-12 hours
  • 1Memorize the phase order and the decision that ends each phase, not just the phase names
  • 2Compare the Cyber Kill Chain, MITRE ATT&CK, and the Diamond Model on one page
  • 3Walk a tabletop scenario from initial alert to lessons learned and write the actions at each step
  • 4Study evidence handling, volatile data order, and chain of custody rules
  • 5Complete an incident response focused lab on TryHackMe or CyberDefenders
Week 9: Reporting, communication, and performance-based practice
8-10 hours
  • 1Write two mock reports from the same finding: one for an engineering team, one for an executive
  • 2Learn the metric definitions cold, including mean time to detect, mean time to respond, and mean time to contain
  • 3Study inhibitors to remediation and the language used to document a risk acceptance
  • 4Do every performance-based question in CertMaster Practice at least twice
  • 5Practise the digital whiteboard, since no physical scratch paper is allowed on the online exam
Week 10: Full-length rehearsal and gap closure
10-12 hours
  • 1Sit two timed 165-minute practice exams on separate days under exam conditions
  • 2Rework every missed item back to the specific CS0-004 objective it came from
  • 3Reread the exam objectives PDF and confirm you can explain every bullet in one sentence
  • 4Run the OnVUE system test if you are testing online and confirm your connection clears CompTIA's 6 Mbps download and 2 Mbps upload minimum
  • 5Confirm your two forms of ID match the name on your CompTIA account exactly

Ready to pass CompTIA CySA+?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$196$98

Best Study Resources

CompTIA CySA+ (CS0-004) exam objectives

Official blueprint

The authoritative list of every testable objective and the four domain weights. Every practice question you answer should trace back to a line in this document.

Free

CompTIA CertMaster Learn

Official eLearning

CompTIA's own course with narrative instruction, videos, flashcards, and interactive performance-based questions. CompTIA estimates 25 to 40 hours to complete.

Paid, often bundled with a voucher

CompTIA CertMaster Practice

Official practice engine

Timed practice exams, objective quizzes, and per-objective mastery scoring. CompTIA estimates 10 to 20 hours. Use the mastery scores to decide what to restudy rather than guessing.

Paid, often bundled

CompTIA CertMaster Labs

Official hands-on labs

Live virtual lab environment with guided SOC scenarios, estimated at 15 to 25 hours. The closest official analogue to the performance-based questions.

Paid

CompTIA CySA+ Study Guide (Sybex)

Book

Mike Chapple and David Seidl's exam guide, the most widely used third-party text for CySA+. Covers every objective with end-of-chapter review questions and includes online practice tests.

Around $50 print

TryHackMe SOC Level 1 path

Hands-on training platform

Browser-based rooms covering log analysis, SIEM, phishing analysis, and endpoint investigation. Directly relevant to the Security Operations and Incident Response domains.

Free tier plus paid subscription

LetsDefend

Blue team simulation platform

Simulated SOC with a live alert queue. Useful for building triage speed, which matters when you have 165 minutes for 85 items including performance-based tasks.

Free tier plus paid subscription

MITRE ATT&CK and ATT&CK Navigator

Framework reference

The tactic and technique matrix CompTIA references directly in the attack methodology objectives. Navigator lets you build coverage heat maps, which is how the framework is used in real SOCs.

Free

FIRST EPSS

Data source

The Exploit Prediction Scoring System, newly emphasized in the V4 vulnerability prioritization objectives. Compare EPSS probability against CVSS severity on real CVEs to understand why the two disagree.

Free

Security Onion

Open source platform

A free network security monitoring distribution bundling Suricata, Zeek, and an Elastic stack. Building and breaking one at home covers more Security Operations objectives than any video course.

Free

Common Mistakes to Avoid

Studying CS0-003 material for a CS0-004 exam date. The two versions overlap heavily, but V4 added AI in security operations, expanded ZTNA and SASE, EPSS-based prioritization, and SBOM and supply chain content that older books do not cover.

Check which exam code your voucher will be used against, then confirm every study resource lists CS0-004. If you are testing before 22 December 2026 you can still sit the English CS0-003 exam, but any later date is V4 only.

Treating performance-based questions as bonus content and leaving them until the last week. They appear early in the exam and can consume 10 to 15 minutes each if you have never used the interface.

Do every performance-based question in CertMaster Practice at least twice, and practise flagging and returning. If a PBQ is not resolving within a few minutes, flag it, bank the multiple-choice points, and come back with whatever time remains of the 165 minutes.

Memorizing tool names instead of tool output. CySA+ shows you scanner results, packet captures, and log excerpts and asks what they mean. Knowing that Nessus is a vulnerability scanner earns nothing when the question shows you its output.

For every tool in the objectives, generate real output at least once in a lab and read it. Run a Nessus Essentials scan, capture traffic in Wireshark, and pull a Windows event log yourself rather than reading screenshots.

Answering vulnerability prioritization questions with CVSS base score alone. V4 explicitly tests risk-based prioritization, where asset value, exploitability, threat intelligence, and EPSS all move the ordering.

Practise scenarios where a CVSS 9.8 on an isolated test box ranks below a CVSS 6.5 on an internet-facing payment system. Score five real CVEs by hand with the CVSS calculator, then look up their EPSS probability and explain the gap.

Skipping Reporting and Communication because it is only 16 percent and feels like soft skills. That is roughly 13 questions on an 85-item exam, and technical candidates routinely lose most of them.

Learn the metric definitions precisely, learn which stakeholder receives which artefact, and learn the named inhibitors to remediation. These are recall questions with exact answers, which makes them the cheapest points on the exam.

Confusing the incident response phase boundaries. Candidates lose points deciding whether isolating a host is containment or eradication, or whether reimaging is eradication or recovery.

Write out the phases and define the exit condition of each one in your own words. Containment ends when the threat cannot spread further, eradication ends when the threat is removed from affected systems, recovery ends when systems are validated back in production.

Assuming a Security+ pass makes CySA+ a short step. CompTIA recommends roughly four years of hands-on SOC or vulnerability management experience on top of Network+ and Security+ level knowledge, and the analysis depth is a genuine jump.

If you have no operational SOC time, replace it with simulated queue work on LetsDefend, Blue Team Labs Online, or CyberDefenders before booking. Time in an alert queue is what the exam is really testing.

Booking the retake immediately after a fail without checking the waiting rule. There is no wait between the first and second attempt, but 14 calendar days are required before the third attempt and every attempt after that.

Plan the second attempt within two to three weeks while the material is fresh, and budget for a full-price voucher because CompTIA offers no free retakes or retake discounts. If you are risk averse, buy a bundle that includes Retake Assurance up front.

Letting the exam voucher expire. A CompTIA voucher is valid for 12 months from issue and the expiry date cannot be extended under any circumstances.

Book the test date at the time you buy the voucher, even if you later reschedule. Rescheduling is free if done more than 24 hours before the appointment; an expired voucher is a total loss.

Exam Day Tips

  • 1

    Bring two forms of valid original identification, and make sure the first and last name on both match the name on your CompTIA account exactly. Photocopies and digital IDs are not accepted.

  • 2

    Check-in opens 30 minutes before your appointment, and CompTIA refuses entry if you are more than 15 minutes late. Log in early rather than on the hour.

  • 3

    If you test online through OnVUE, run the system test days in advance on the exact machine and network you will use. CompTIA requires at least 6 Mbps download and 2 Mbps upload, a single display with any second monitor disconnected and powered down, and a private connection rather than a corporate network or VPN.

  • 4

    Clear the desk completely before check-in. You will photograph your workspace, and the room scan must show no books, paper, pens, second monitors, or additional computers. You will not be allowed to start until the scan passes.

  • 5

    There is no physical scratch paper. Use the built-in digital whiteboard, and practise with it before exam day so you are not learning the interface while a subnet calculation waits.

  • 6

    No food or drink at the desk, and no phone within arm's reach. CompTIA requires drinks, notes, and devices to be beyond arm's reach for online sessions; at a Pearson VUE centre everything goes into a locker before check-in.

  • 7

    Do not photograph or screenshot any part of the exam, including the score screen at the end. CompTIA treats this as a policy violation that can invalidate your score and revoke the certification.

  • 8

    Keep an eye on the 165-minute clock against the 85-item maximum. That is under two minutes per item, and performance-based questions will eat far more than that if you let them.

  • 9

    Use the Contact Proctor option inside OnVUE for technical problems while the exam is running. Proctors do not discuss content, and CompTIA states they cannot pause your exam, add time, or fix your equipment, so anything you can settle before check-in is worth settling then.

  • 10

    Your preliminary pass or fail appears immediately on screen. If you pass, log in to your CompTIA account afterwards to request the certificate and claim the digital badge.

Career Paths & Salary Ranges

SOC analyst (tier 1 and tier 2)

Works the alert queue, triages detections from SIEM and EDR, escalates confirmed incidents, and tunes noisy rules. The role the exam is most directly built around, and the one CompTIA lists first in its CySA+ role mapping.

Lower to middle of the $75k-$110k CySA+ band

Incident response analyst

Owns investigations end to end from detection through containment, eradication, recovery, and lessons learned. CySA+ maps to the cyber defense incident responder DCWF work role, which matters for federal and defence contractor hiring.

Middle to upper part of the $75k-$110k CySA+ band

Vulnerability management analyst

Runs the scanning programme, validates findings, prioritizes remediation using CVSS, EPSS, and asset context, and negotiates fix timelines with engineering teams. Roughly a quarter of the exam maps to this job directly.

Middle of the $75k-$110k CySA+ band

Threat intelligence analyst

Collects and evaluates intelligence, maps adversary behaviour to MITRE ATT&CK, and turns reporting into detections and hunting hypotheses. Requires the threat intelligence and hunting objectives from Domain 1 at working depth.

Upper part of the $75k-$110k CySA+ band

Security engineer or SOC engineer

Builds and maintains the detection stack rather than working the queue: SIEM content, SOAR playbooks, EDR policy, and log pipeline health. The Domain 1 process improvement and automation objectives feed straight into this path.

Upper part of the $75k-$110k CySA+ band

Compliance or risk analyst

Translates vulnerability and incident data into compliance reporting and risk narratives for auditors and executives. The Reporting and Communication domain is the bridge, and this path often leads towards CISA or CRISC next.

Lower to middle of the $75k-$110k CySA+ band

Prerequisites & Requirements

  • No enforced prerequisites. CompTIA lets anyone buy a voucher and sit CySA+ without proving prior certification or experience.
  • CompTIA recommends CompTIA Network+ and CompTIA Security+ or equivalent knowledge before attempting the exam.
  • CompTIA recommends about four years of hands-on experience as a SOC analyst, incident response analyst, or vulnerability analyst.
  • CompTIA advises against skipping Security+ unless you already have substantial cybersecurity experience, on the grounds that you need to understand how a network works and how to secure it before you can analyze it.
  • Comfort with reading logs, packet captures, and scanner output matters more than any certificate you already hold, because the performance-based questions assume it.

Frequently Asked Questions

How much does the CompTIA CySA+ exam cost?

CompTIA lists the United States retail price for the CySA+ V4 exam voucher at $425. There is no price difference between testing at a Pearson VUE centre and testing online through OnVUE. Prices are set per region and per currency, so the figure differs outside the United States. Bundles that combine a voucher with CertMaster Learn, Practice, or Perform cost more up front but less than buying the pieces separately, and actively registered students at four-year institutions in the United States can verify through SheerID for 35 to 55 percent off products in the CompTIA store.

What happens if I fail the CySA+ exam?

You can retake it immediately with no waiting period between the first and second attempt. Before your third attempt and any subsequent attempt, CompTIA requires you to wait at least 14 calendar days from the date of your last attempt. You must pay the full exam price for every attempt, because CompTIA does not offer free retests or retake discounts. Your score report breaks results down by domain, so use it to target restudy rather than repeating the whole syllabus.

Should I take CS0-003 or CS0-004?

Take CS0-004 unless you are testing before 22 December 2026 and are already deep into V3 material. CompTIA retires the English CS0-003 exam on 22 December 2026, retires English CS0-003 learning products on 22 November 2026, and retires the Japanese, Portuguese, and Spanish translations on 23 March 2027. V4 launched on 23 June 2026 and adds AI in security operations, expanded ZTNA and SASE, EPSS-based vulnerability prioritization, and SBOM and supply chain content. Both certifications carry the same name and the same three-year validity once earned.

What is the passing score and how is it calculated?

You need 750 on a scale of 100 to 900. CompTIA does not publish the number of raw items you must answer correctly to reach 750, and the scale is not a percentage, so a 750 is not 83 percent. Performance-based questions carry different point values than multiple-choice items, and CompTIA does not publish those values either. The practical implication is that you cannot compute a safety margin in advance, so aim for consistent scores well above passing on official practice tests rather than trying to reverse-engineer the cut score.

How long does it take to get CySA+ results?

Immediately. Your preliminary pass or fail status appears on screen as soon as you finish the exam, both at test centres and online. If you pass, the score report tells you to log in to your CompTIA account to request your wallet ID card and official certificate, and you can claim your digital badge from there. You may not photograph or screenshot the results screen, which CompTIA treats as a policy violation serious enough to invalidate scores.

What identification do I need on exam day?

Two forms of valid identification, presented via webcam for online exams or at the desk for test centre exams. The first and last name used to register must match the names on both IDs, and both must be originals rather than photocopies. Candidates aged 17 and under need only a single form of ID, a school ID is acceptable for them, and they need guardian authorization for each testing event with the guardian present at check-in showing their own government-issued ID.

Can I use a calculator or any reference material?

No. The workspace must be completely clear of books, paper, pens, and notes, and no second monitor or additional computer may be connected. Online candidates get a built-in digital whiteboard for scratch work instead of paper. Nothing in the CySA+ objectives requires arithmetic beyond what you can do mentally or on the whiteboard, so the absence of a calculator is not the constraint candidates fear.

How does online proctoring work for CySA+?

Online delivery runs through Pearson OnVUE. You download the OnVUE software before exam day, run a system test, and check in through a process that photographs you and your workspace and requires a room scan you must pass before starting. You must be alone in a walled room with a closed door for the whole exam. A proctor watches by camera and will warn you if your eyes wander from the screen. You can chat with the proctor about technical problems but not about exam content, and any technical issue has to be raised during the exam rather than afterwards.

Are accommodations available for CySA+?

Yes, on a case-by-case basis. CompTIA directs candidates to request accommodations from Pearson VUE, and accommodations for online proctored exams are considered individually. CompTIA also notes that for online exams, time accommodations can be handled by stopping the exam at any point by closing the browser, which pauses the clock and lets you resume, provided you are still inside the allotted window and the exam time has not run out.

How long is CySA+ valid and how do I renew it?

Three years from the date you pass. You renew through the CompTIA Continuing Education program, either with a single qualifying activity or by accumulating 60 CEUs across the three-year cycle. Single-activity options include completing CompTIA CertMaster CE, earning a higher-level CompTIA certification, earning a qualifying non-CompTIA industry certification, or passing the latest release of the CySA+ exam. If you renew by uploading CEUs, the CE fee is $150 across the three-year period, payable in CE tokens sold at $25 and $50. Renewing with CertMaster CE or a higher CompTIA certification waives that fee.

Does CySA+ renew my Security+?

Yes. CySA+ sits above Security+ in the CompTIA cybersecurity pathway, so earning it automatically renews eligible lower-level CompTIA certifications including Security+. You also only pay CE fees for your highest-level CompTIA certification, and renewing that one renews the lower-level ones without additional fees. The exception CompTIA flags is that fees are not waived when the higher-level certification does not fully renew the lower-level one.

How does CySA+ compare to Security+?

Security+ is the foundational certification and CySA+ is the intermediate analyst certification above it. CompTIA frames the difference as scope and depth: Security+ validates that you understand cybersecurity concepts, while CySA+ validates that you can apply them in an operational environment. Security+ runs 90 minutes with a maximum of 90 questions; CySA+ runs 165 minutes with a maximum of 85 questions, and the extra time reflects heavier analysis and more performance-based work. Both use the 100 to 900 scale with 750 passing.

How does CySA+ compare to PenTest+?

They are the two halves of the same job. CySA+ is defensive and covers detection, vulnerability management, and incident response; PenTest+ is offensive and covers scoping, reconnaissance, exploitation, and reporting on a penetration test. Both sit at the same level in CompTIA's cybersecurity pathway, both recommend Network+ and Security+ first, and both are valid for three years with 60 CEUs to renew. PenTest+ runs 165 minutes with a maximum of 90 questions against CySA+ at a maximum of 85.

Is CySA+ approved for United States Department of Defense requirements?

Yes. CompTIA states that CySA+ is approved under DoD Directive 8140.03M and that the program is ISO 17024 compliant. CompTIA maps CS0-003 to ten DoD Cyber Workforce Framework work roles: all source analyst, warning analyst, forensics analyst, cyber defense forensics analyst, cyber crime investigator, systems security analyst, cyber defense analyst, cyber defense incident responder, vulnerability assessment analyst, and security control assessor. This mapping is the reason the certification appears on so many cleared job postings.

How many hours of study does CySA+ actually need?

CompTIA estimates 30 to 55 hours of studying and practice for a candidate who already meets the recommended experience level. That assumption matters: CompTIA also recommends roughly four years of hands-on SOC, incident response, or vulnerability management experience. If you do not have that, budget substantially more and spend the extra time on hands-on alert triage rather than reading. CompTIA's own product estimates give a sense of scale, at 25 to 40 hours for CertMaster Learn, 10 to 20 for CertMaster Practice, and 15 to 25 for CertMaster Labs.

How long is a CompTIA exam voucher valid?

Twelve months from the date you receive it, and CompTIA states the expiration date cannot be extended under any circumstances. A voucher can be used for any version of the certification exam as long as you sit the exam before it expires, so a voucher bought during the CS0-003 window can still be used against CS0-004. You must reschedule an appointment at least 24 hours in advance, and a retake option attached to a bundle only activates after you have taken and not passed the exam.

Can I retake CySA+ after passing it to refresh the certification?

Not with the same exam code. CompTIA's retake policy prohibits retaking an exam you have already passed under the same code without prior consent, so you would need to wait for a new series to be released. That is why passing the latest release of your CompTIA exam counts as a renewal activity: once CS0-005 eventually appears, holders of a CS0-004 based certification can sit it to renew. Violating the retake policy results in an invalidated test and possible suspension.

50% OFF

Pass CompTIA CySA+, Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $98
$98
$19650% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee, Pass or get 100% refund