CompTIA CySA+ Lessons

Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.

Practise with the exam simulator

  1. What a security operations centre actually doesObjective 1.1
  2. Building a detection lab you can break
  3. Network architecture, read the way an analyst reads itObjective 1.1
  4. Identity as the new perimeterObjective 1.1
  5. Logging: what to collect, and what you will regret not collectingObjective 1.1
  6. Reading malicious activity on the networkObjective 1.2
  7. Reading malicious activity on a hostObjective 1.2
  8. Malicious activity in applications and cloud servicesObjective 1.2
  9. Account compromise and identity-based attacksObjective 1.2
  10. SIEM: searching, correlating and not drowningObjective 1.3
  11. EDR and what it can and cannot seeObjective 1.3
  12. Packet analysis when the logs are not enoughObjective 1.3
  13. Threat intelligence that changes what you doObjective 1.4
  14. Threat hunting: looking without an alertObjective 1.4
  15. Automation, orchestration and getting time backObjective 1.5
  16. AI in security operations: uses, risks and governanceObjective 1.6
  17. Choosing the right scan for the questionObjective 2.1
  18. Knowing what you have before you scan itObjective 2.1
  19. Scanning web applications and APIsObjective 2.1
  20. Reading scanner output without believing all of itObjective 2.2
  21. Vulnerabilities in cloud and containersObjective 2.2
  22. CVSS, and what a score does not tell youObjective 2.3
  23. Prioritising with business contextObjective 2.3
  24. Fixing, mitigating and acceptingObjective 2.3
  25. Supply chain and dependency riskObjective 2.4
  26. Controls, frameworks and where findings hangObjective 2.4
  27. MITRE ATT&CK, the kill chain and the diamond modelObjective 3.1
  28. The incident response lifecycleObjective 3.2
  29. Preparation: the phase that decides the other fourObjective 3.2
  30. Triage: deciding what this actually isObjective 3.3
  31. Evidence that survives scrutinyObjective 3.3
  32. Containing without destroying what you needObjective 3.3
  33. Enough malware analysis to make a decisionObjective 3.3
  34. Responding to ransomware and extortionObjective 3.3
  35. Root cause, and making the lesson stickObjective 3.3
  36. Vulnerability reporting people will act onObjective 4.1
  37. Communicating with the people who own the fixObjective 4.1
  38. Incident documentation as you go, not afterObjective 4.2
  39. Communicating while the incident is still runningObjective 4.2
  40. Metrics that change behaviourObjective 4.2