CompTIA CySA+ Lessons
Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.
- What a security operations centre actually doesObjective 1.1
- Building a detection lab you can break
- Network architecture, read the way an analyst reads itObjective 1.1
- Identity as the new perimeterObjective 1.1
- Logging: what to collect, and what you will regret not collectingObjective 1.1
- Reading malicious activity on the networkObjective 1.2
- Reading malicious activity on a hostObjective 1.2
- Malicious activity in applications and cloud servicesObjective 1.2
- Account compromise and identity-based attacksObjective 1.2
- SIEM: searching, correlating and not drowningObjective 1.3
- EDR and what it can and cannot seeObjective 1.3
- Packet analysis when the logs are not enoughObjective 1.3
- Threat intelligence that changes what you doObjective 1.4
- Threat hunting: looking without an alertObjective 1.4
- Automation, orchestration and getting time backObjective 1.5
- AI in security operations: uses, risks and governanceObjective 1.6
- Choosing the right scan for the questionObjective 2.1
- Knowing what you have before you scan itObjective 2.1
- Scanning web applications and APIsObjective 2.1
- Reading scanner output without believing all of itObjective 2.2
- Vulnerabilities in cloud and containersObjective 2.2
- CVSS, and what a score does not tell youObjective 2.3
- Prioritising with business contextObjective 2.3
- Fixing, mitigating and acceptingObjective 2.3
- Supply chain and dependency riskObjective 2.4
- Controls, frameworks and where findings hangObjective 2.4
- MITRE ATT&CK, the kill chain and the diamond modelObjective 3.1
- The incident response lifecycleObjective 3.2
- Preparation: the phase that decides the other fourObjective 3.2
- Triage: deciding what this actually isObjective 3.3
- Evidence that survives scrutinyObjective 3.3
- Containing without destroying what you needObjective 3.3
- Enough malware analysis to make a decisionObjective 3.3
- Responding to ransomware and extortionObjective 3.3
- Root cause, and making the lesson stickObjective 3.3
- Vulnerability reporting people will act onObjective 4.1
- Communicating with the people who own the fixObjective 4.1
- Incident documentation as you go, not afterObjective 4.2
- Communicating while the incident is still runningObjective 4.2
- Metrics that change behaviourObjective 4.2