CompTIA CySA+ Cybersecurity Analyst
- Course Code GK5867
- Duration 5 days
- Version CS0-004
Course Delivery
Additional Payment Options
-
GTC 37 inc. VAT
GTC, Global Knowledge Training Credit, please contact Global Knowledge for more details
Jump to:
Course Delivery
This course is available in the following formats:
-
Company Event
Event at company
-
Public Classroom
Traditional Classroom Learning
-
Virtual Learning
Learning that is virtual
Request this course in a different delivery format.
Course Overview
TopLearn how to detect ,analyze, and protect critical infrastructures using threat-detection and threat-analysis tools.
Gain the tools and tactics to manage cybersecurity risks, identify various types of common threats, evaluate an organization's security, collect and analyze cybersecurity intelligence, and handle incidents as they occur. This is a comprehensive approach to security aimed toward those on the front lines of defense.
This course is designed to assist students in preparing for the CompTIA CySA+ - Cybersecurity Analyst+ (CS0-004) certification exam.
CompTIA’s CySA+ is a global vendor-neutral certification covering intermediate-level knowledge and skills required by information security analyst job roles. It helps identify a cybersecurity professional’s ability to proactively defend an organization using secure monitoring, threat identification, incident response and teamwork. The CompTIA CySA+ CS0-004 certification exam ensures the candidate has the knowledge and skills required to:
- Identify and investigate suspicious activity across networks, endpoints, and cloud environments to uncover potential security threats.
- Identify, prioritize, and mitigate vulnerabilities using risk-based vulnerability management approaches.
- Investigate and respond to cybersecurity incidents using structured incident response processes and real-world techniques.
- Use modern security operations concepts, including threat intelligence, threat hunting, automation, and AI-assisted security operations.
Updated 30/7/2026
Course Schedule
Top-
- Delivery Format: Virtual Learning
- Date: 10-14 August, 2026 | 9:30 AM to 5:00 PM Guaranteed To Run Late Availability
- Location: Virtual (GMT Standa)
- Language: English
-
Guaranteed To Run
-
Late Availability
-
- Delivery Format: Virtual Learning
- Date: 21-25 September, 2026 | 8:00 AM to 4:00 PM
- Location: Virtual (GMT Standa)
- Language: English
-
- Delivery Format: Virtual Learning
- Date: 21-25 September, 2026 | 8:00 AM to 4:00 PM
- Location: Virtual (GMT Standa)
- Language: English
-
- Delivery Format: Virtual Learning
- Date: 28 September-02 October, 2026 | 9:30 AM to 5:00 PM
- Location: Virtual (GMT Standa)
- Language: English
-
- Delivery Format: Virtual Learning
- Date: 16-20 November, 2026 | 9:30 AM to 5:00 PM
- Location: Virtual (GMT Standa)
- Language: English
-
- Delivery Format: Virtual Learning
- Date: 07-11 December, 2026 | 8:00 AM to 4:00 PM
- Location: Virtual (GMT Standa)
- Language: English
Target Audience
Top- Security Operations Center (SOC) Analyst
- Vulnerability Analyst
- Cybersecurity Specialist
- Threat Intelligence Analyst
- Security Engineer
Course Objectives
Top- Identify and investigate suspicious activity across networks, endpoints, and cloud environments to uncover potential security threats.
- Monitor and analyze data using industry-standard tools such as SIEM and EDR platforms.
- Identify, prioritize, and mitigate vulnerabilities using risk-based approaches.
- Investigate and respond to security incidents using structured processes and real-world techniques.
- Clearly communicate security findings and risks to stakeholders through reports and dashboards.
- Apply security practices across cloud and hybrid environments while supporting efficient and effective operations.
Course Content
TopCourse Modules
- Identifying Security Operations Fundamentals
- Applying Risk Management Strategies
- Managing System Security and Configurations
- Comparing System Architectures
- Applying Access Management
- Threat Intelligence and Threat Hunting
- Assessing Network Vulnerabilities
- Managing Incident Response and Communication
- Executing Incident Response Plans
- Analyzing Malicious Activity
- Automating Data Analysis
- Improving Processes with Automation
- Assessing Application Vulnerabilities
- Securing Applications
LABS
- Live Lab: Operate A SOC Workstation
- Applied Live Lab: Assess Attack Surface And System Hardening
- Live Lab: Deploy A CI/CD Cloud Application
- Live Lab: Deploy A CI/CD Container Application
- Live Lab: Configure Federated Authentication And PAM
- Applied Live Lab: Apply Data Protection And Endpoint Security
- Live Lab: Configure A Honeypot
- Live Lab: Implement Threat Intelligence
- Applied Live Lab: Analyze Vulnerability Scans
- Live Lab: Configure Centralized Logging
- Live Lab: Use A Playbook For Incident Response
- Live Lab: Record Case Evidence
- Live Lab: Create Log Analysis Queries
- Live Lab: Configure A Sandbox
- Applied Live Lab: Analyze Anomalous Host Activity
- Network Indicators of Compromise
- Applied Live Lab: Analyze Anomalous Network Activity
- Application and Web-based Indicators
- Live Lab: Analyze Phishing Emails
- Challenge Live Lab: Resolve Incident Response Cases
- Live Lab: Implement An Automation Solution
- Live Lab: Perform Rule Tuning
- Live Lab: Add AI To An Incident Response Playbook
- Applied Live Lab: Analyze Cloud Infrastructure Vulnerabilities
- Applied Live Lab: Analyze Web Service Vulnerabilities
- Live Lab: Integrate Security Scanning In A CI/CD Pipeline
- Challenge Live Lab: Resolve Cloud And App Vulnerabilities
Course Prerequisites
TopTo ensure your success in this course, you should meet the following requirements:
- At least two years (recommended) of experience in computer network security technology or a related field.
- The ability to recognize information security vulnerabilities and threats in the context of risk management.
- Foundation-level operational skills with some of the common operating systems for computing environments.
- Foundational knowledge of the concepts and operational framework of common assurance safeguards in computing environments. Safeguards include, but are not limited to, basic authentication and authorization, resource permissions, and anti-malware mechanisms.
- Foundation-level understanding of some of the common concepts for network environments, such as routing and switching.
- Foundational knowledge of major TCP/IP networking protocols including, but not limited to, TCP, IP, UDP, DNS, HTTP, ARP, ICMP, and DHCP.
- Foundational knowledge of the concepts and operational framework of common assurance safeguards in network environments. Safeguards include, but are not limited to, firewalls, intrusion prevention systems, and VPNs.
Test Certification
TopThis course is designed to assist students preparing for the CompTIA CySA+ - Cybersecurity Analyst+ (CS0-004) certification exam. What you learn and practice in this course can be a significant part of your preparation.
Exam details
Exam series code: CS0-004
Number of Questions: Maximum of 85 questions
Length of Test: 165 minutes
Passing Score: 750 (on a scale of 100-900)
Recommended experience: About 4 years in a SOC analyst or vulnerability analyst role