← All certifications

CompTIA · CS0-004 · 2026-06 objectives

CompTIA CySA+

211
questions
8
practice tests
1
free test
750 / 900
to pass the real exam

Try 5 questions

Real questions from the CySA+ bank, one per domain. No account, no card needed! Just choose an answer and see the why.

1 / 5OBJ 1.1

To ensure that log entries from many systems can be reliably correlated during an investigation, which service must be consistently configured across all hosts?

Practice tests

Timed and scored like the real thing. Answers stay on the server until you submit, then every question is explained in review.

Exam objectives

What CS0-004 covers, and how much of the exam each domain accounts for. Percentages are the share of scored questions in the 2026-06 objectives.

1.0Security Operations

34%
  • 1.1Explain concepts related to system and network architecture in security (Ingestion, Configuration, Integrity and security, Time synchronization, Retention, System hardening).
  • 1.2Given a scenario, analyze indicators of potential malicious activity (Rogue devices, Enumeration, Anomalous activity, Activity on unexpected ports, Resource consumption, Unauthorized software).
  • 1.3Given a scenario, use tools to determine malicious activity (Decoding/parsing, Packet analysis, Log analysis, Threat-intelligence platforms, Endpoint security, Domain and IP reputation).
  • 1.4Explain threat intelligence and threat-hunting concepts (Advanced persistent threat (APT), Insider threat, Heat maps, Pyramid of Pain, MITRE ATT&CK, Attribution).
  • 1.5Explain the importance of efficiency and process improvement in security (Manage and facilitate team coordination, Playbook/runbook creation, Automation and orchestration, Data enrichment, APIs, Webhooks).
  • 1.6Summarize concepts related to the use of AI in security operations (Hallucinations, Data exposure, Model poisoning, Malicious prompts, Legal or regulatory compliance, AI usage policies).

2.0Vulnerability Management

26%
  • 2.1Given a scenario, implement the appropriate vulnerability scanning method (Scheduling, Operations, Performance, Sensitivity levels, Segmentation, Regulatory requirements).
  • 2.2Given a scenario, analyze output from vulnerability assessment tools (Angry IP Scanner, Masscan, Nmap, Metasploit Framework (MSF), Maltego, Recon-ng).
  • 2.3Given a scenario, analyze data to prioritize and mitigate vulnerabilities (Exploitability, Active exploitation/threat intelligence, Asset value, Impact, Patch/remediation availability, True/false positives).
  • 2.4Explain concepts related to control types, risks, and vulnerability (Administrative, Technical, Physical, Preventative, Detective, Responsive).

3.0Incident Response and Management

24%
  • 3.1Summarize concepts related to attack methodology frameworks (Cyber Kill Chain, Diamond Model of Intrusion Analysis, MITRE ATT&CK).
  • 3.2Summarize the incident response process (Preparation, Detection, Analysis, Containment, Eradication, Recovery).
  • 3.3Given a scenario, implement incident response techniques (Incident response plan, Communication plan, Tabletop, Simulation, Chain of custody, Data integrity validation).

4.0Reporting and Communication

16%
  • 4.1Explain the importance of vulnerability management reporting and (Escalation, Dependencies, Contractual agreements, Organizational governance, Business process interruption, Degrading functionality).
  • 4.2Explain the importance of security operations and incident response reporting (Stakeholder identification, Legal team, Public relations, Regulatory reporting agencies, Law enforcement, Customers).

Summarized from CompTIA CySA+’s published exam objectives. Always check the vendor’s current objectives before your exam.