CompTIA

CompTIA Cybersecurity Analyst+ (CySA+) CT-04B

CompTIA Cybersecurity Analyst (CySA+) Training

Not sure this is the right class? Read Which CompTIA Class Should I Take?

  • 4 upcoming dates 4 open for booking
  • $2,495 per seat

Upcoming dates

Dates Where Status Seat Book
Oct 12–16 2026 Live Online 6:00 AM to 2:00 PM PT Confirmed to run Partner led $2,495
Nov 16–20 2026 Live Online 6:00 AM to 2:00 PM PT Confirmed to run Partner led $2,495
Dec 7–11 2026 Live Online 6:00 AM to 2:00 PM PT Confirmed to run Partner led $2,495
Jan 11–15 2027 Live Online 6:00 AM to 2:00 PM PT Confirmed to run Partner led $2,495

See every class on the schedule

About this class

This five-day, instructor-led course is intended for those wishing to qualify with CompTIA CSA+ Cybersecurity Analyst Certification. CompTIA's CSA+ Certification is an intermediate-level certificate for IT professionals with previous experience of working in the field of IT security. The CompTIA CSA+ examination is designed for IT security analysts, vulnerability analysts, or threat intelligence analysts. The exam will certify that the successful candidate has the knowledge and skills required to configure and use threat detection tools, perform data analysis, and interpret the results to identify vulnerabilities, threats, and risks to an organization with the end goal of securing and protecting applications and systems within an organization.

This courseware bears the seal of CompTIA Approved Quality Content. This seal signifies this content covers 100% of the exam objectives and implements important instructional design principles. CompTIA recommends multiple learning tools to help increase coverage of the learning objectives. The contents of this training material were created for the CompTIA CSA+ Cybersecurity Analyst Certification CS0-002 exam.

CompTIA CSA+ certification is aimed at IT professionals with (or seeking) job roles such as IT Security Analyst, Security Operations Center (SOC) Analyst, Vulnerability Analyst, Cybersecurity Specialist, Threat Intelligence Analyst, and Security Engineer

This course will teach you the fundamental principles of using threat and vulnerability analysis tools plus digital forensics tools. It will prepare you to take the CompTIA Cybersecurity Analyst+ CS0-002 exam by providing 100% coverage of the objectives and content examples listed on the syllabus. Study of the course can also help to build the prerequisites to study more advanced IT security qualifications

Please call or email for information about setting up a dedicated class for your organization

What you'll be able to do

  • Assessing Information Security Risk
  • Analyzing Reconnaissance Threats to Computing
  • Analyzing Attacks on Computing and Network
  • Analyzing Post -Attack Techniques
  • Managing Vulnerabilities in the Organization
  • Collecting Cybersecurity Intelligence
  • Analyzing Log Data
  • Performing Active Asset and Network Analysis
  • Responding to Cybersecurity Incidents
  • Investigating Cybersecurity Incidents
  • Addressing Security Architecture Issues

Course outline

  1. Module 1Assessing Information Security Risk

    • Understand the importance of risk management
    • Perform risk assessments across systems and networks
    • Apply risk mitigation strategies
    • Integrate documentation into the risk management process
  2. Module 2Analyzing Reconnaissance Threats to Computing

    • and Network Environments
    • Evaluate the impact of reconnaissance activities
    • Assess the risks posed by social engineering attacks
  3. Module 3Analyzing Attacks on Computing and Network

    • Environments
    • Analyze the impact of system hacking attempts
    • Evaluate the effects of web- based attacks
    • Assess malware threats and their consequences
    • Understand hijacking and impersonation attacks
    • Analyze Denial - of - Service (DoS) incidents
    • Examine mobile security threats
    • Explore cloud security risks
  4. Module 4Analyzing Post -Attack Techniques

    • Identify command and control methods
    • Assess techniques for maintaining persistence
    • Analyze lateral movement and pivoting strategies
    • Understand data exfiltration methods
    • Examine anti - forensics techniques
  5. Module 5Managing Vulnerabilities in the Organization

    • Implement a comprehensive vulnerability management plan
    • Identify and assess common system and application vulnerabilities
    • Conduct vulnerability scans effectively
    • Perform penetration testing on network assets
  6. Module 6Collecting Cybersecurity Intelligence

    • Set up platforms for collecting and analyzing security intelligence
    • Gather data from network - based intelligence sources
    • Collect intelligence from host - based sources
  7. Module 7Analyzing Log Data

    • Utilize common tools to analyze log files
    • Leverage SIEM (Security Information and Event Management) tools for deeper
    • analysis
  8. Module 8Performing Active Asset and Network Analysis

    • Investigate incidents using Windows - based tools
    • Analyze events using Linux - based tools
    • Perform basic malware analysis
    • Examine indicators of compromise (IOCs)
  9. Module 9Responding to Cybersecurity Incidents

    • Deploy an effective incident response architecture
    • Mitigate active threats
    • Prepare your CSIRT team for forensic investigation
  10. Module 10Investigating Cybersecurity Incidents

    • Apply a structured forensic investigation plan
    • Securely collect and analyze electronic evidence
    • Conduct post - investigation follow - up and reporting
  11. Module 11Addressing Security Architecture Issues

    • Resolve identity and access management (IAM) problems
    • Integrate security considerations throughout the Software Development Life Cycle
    • (SDLC)

Download the full outline (PDF)

Before you attend

Four or more years of information security experience. Ideally, you should have successfully completed CompTIA Network+ Certification AND Security+ Certification courses or have equivalent knowledge before attending this training

Run this for a team

Private cohorts run on your dates, at your site or online, with the labs pointed at your environment. Above about four people it usually costs less than buying seats.

Or call 916-920-1700, weekdays 8 to 5 Pacific.

More security classes

See all