
Discover what a cybersecurity analyst does and how CySA+ exam covers domains: threat and vulnerability management, security operations and monitoring, software and system security, incident response, and compliance and assessment.
Learn open source intelligence (osint) to map your threat surface using websites, job listings, and LinkedIn; use harvester and showdown to gather emails, subdomains, and technologies.
Explore cyber threat intelligence foundations by examining STIX, TAXII, and indicator management, and learn how openIoC and MISP enable structured, shareable data for threat analysis.
Explore confidence levels and standardized threat language to improve threat modeling and risk assessment. Learn the admiralty scale, information reliability, and estimative language for clear, interoperable communication.
Explore threat classification through the known knowns, known unknowns, unknown knowns, and unknown unknowns framework, with zero-days, bug bounties, and advanced persistent threats guiding threat modeling.
Explore threat actors from script kiddies to insiders, including recreational hackers, professional hackers, cyber criminals, hacktivists, state-sponsored actors, terrorists, and insider threats, focusing on knowledge levels, motivations, and intents.
Define the intelligence cycle and its five phases—planning and direction, collection, analysis, dissemination, and feedback—and show how intelligence requirements guide secure data handling for strategic, operational, and tactical audiences.
Define commodity malware as off-the-shelf, widely available malicious software used for opportunistic, untargeted attacks, contrasted with advanced, targeted malware used by APT groups.
Explore how information sharing and analysis centers coordinate industry threat intelligence across healthcare, finance, aviation, and government sectors to bolster cyber resilience and risk reduction.
Examine attack frameworks to threat model and defend organizations, covering the cyber kill chain, Mitre ATT&CK, and the Diamond Model, and apply threat hunting for indicators of compromise.
Explore threat research to understand threats targeting your organization, including reputational threats, indicators of compromise, and behavioral TTPs guided by MITRE ATT&CK to strengthen defenses.
Explore threat modeling methodologies, adversary capabilities, attack surface and vectors, and risk assessment to determine impact and likelihood of security breaches.
Explore how threat intelligence shapes risk management, security engineering, incident response, vulnerability management, and detection and monitoring by guiding risk reduction, reducing the threat surface, attribution, and proactive detection.
Identify and validate vulnerabilities by assessing asset criticality, performing active and passive scans, enumerating services and versions, and validating findings to prioritize risk.
Establish baselines to define normal system behavior, then apply remediation and mitigation for vulnerabilities. Patch, harden, and implement compensating controls, and verify mitigations by re-scanning with Nessus.
Navigate vulnerability scanning parameters and criteria, from risk assessment and feed updates to scoping, scan types (credentialed and non-credentialed; internal vs external), and workflow considerations.
Identify inhibitors to remediation, including legacy systems, proprietary systems, degraded functionality from patches, business process disruption, governance and change management bottlenecks, and contract constraints.
Learn to interpret web app scanner outputs and identify issues in web applications. Compare OWASP ZAP, Burp Suite, Nikto, and Arachni, and learn how to analyze scanner alerts.
Analyze vulnerability scanner outputs and prioritize remediation across Nessus, OpenVAS, and Qualys, including high-risk SMB share issues and validation of findings from the scans.
Explore static and dynamic software assessment tools to identify vulnerabilities, using automation and manual code review, fuzzing, and reverse engineering to secure applications.
Explore vulnerability enumeration using Nmap, Hping3, and Responder to discover hosts and open ports. Identify services, versions, and risks like LLMNR poisoning and hash capture.
Explore wireless assessment tools like Reaver and the Aircrack-ng suite to test WPS and WPA/WPA2 security, capture handshakes, and crack passwords with dictionary attacks using Hashcat.
Explore open source tools for assessing cloud security and security posture, including ScoutSuite, Prowler, and Pacu, to audit multi-cloud and AWS configurations, report findings, and spot misconfigurations.
Understand how BYOD expands threat surfaces through deperimeterization and lost devices, and how MDM/EMM secure data with encryption, controlled apps, and centralized management via AirWatch or MobileIron.
Learn threats to building automation and vehicle systems, including PLC vulnerabilities, buffer overflows, hardcoded credentials and cryptographic keys, web-based interfaces, and CAN bus risks via OBD-II ports and wireless access.
Explore controller systems, including ICS/SCADA, PLCs, MODBUS, HMIs, and DCS, and their security threats. Examine web app risks like injection and DoS, Stuxnet-style attacks, with TLS as a mitigation.
Explore IoT and embedded systems threats, including embedded operating systems, real-time OS, and FPGA risks. Learn how CVEs, remote access, and supply-chain attacks compromise devices and how to mitigate.
Explore CVSS metrics from base through temporal and environmental metrics, and learn how access vector, complexity, privileges, user interaction, scope, and confidentiality, integrity, availability drive severity for prioritization.
Explore threats across cloud deployment models—public, private, hybrid, and community—including multi-tenancy, encryption, and compliance. Learn how identity authentication, authorization, and accounting, redundancy, and defined roles help secure these environments.
Explore threats in cloud service models, including phishing, account compromise, and data exfiltration, and examine customer and provider responsibilities, OWASP top 10 risks, and cloud data permissions.
Examine function as a service and other cloud threats, including insecure APIs and misconfigured storage. Learn how infrastructure as code and key management mitigate these risks.
Explore mitigations for XML external entity, SQL injection, overflow, remote code execution, directory traversal, privilege escalation, password attacks, impersonation, mitm, session hijacking, rootkits, cross-site scripting via input sanitization and patching.
Explore vulnerability types such as improper error handling, insecure direct object references, SQL injection, and race conditions, and learn mitigations through secure coding, authentication controls, and patching.
Explore asset tagging and change management to catalog assets, track details and locations, manage warranties, and implement controlled changes that protect availability and the CIA triad.
Learn how to design a secure network using architecture and segmentation, from physical controls and VLANs to software defined networking, VPNs, and cloud concepts like VPCs and serverless functions.
Explore identity and access management fundamentals, including privileged management and DAC, MAC, RBAC, ABAC, MFA, SSO, federation, and manual review.
Explore how virtual desktop infrastructure and containerization boost security with non-persistent desktops, thin clients, and server-side images. Use Docker to create consistent, cross-platform environments that reduce drift and enable recovery.
Explore honeypots and active defense to frustrate attackers, slow their progress, and gather intel by using obfuscation, port hiding, fake portals, and dummy infrastructure, with OpenCanary and Honeybadger demonstrations.
Cloud access security broker (CASB) integrates enterprise security policies with cloud apps, enabling single sign-on, access controls, malware scanning, and visibility, via forward proxies, reverse proxies, or API integrations.
Master certificate management by installing, updating, and revoking certificates, maintaining trusted roots, and avoiding self-signed certs in production environments.
Explore hardware assurance fundamentals, including the trusted platform module, hardware security modules, anti-tamper, and secure firmware updates to protect data at rest and in transit.
Explore software assurance and secure coding within the secure development lifecycle, and apply input validation, output encoding, and prepared statements to prevent xss and sql injection.
Explore the components of trend analysis to predict security outcomes, using frequency, volume, and deviation against baselines, and apply metrics like alerts, incidents, response times, and compliance.
Identify url analysis components, including domain, path, and query strings, and examine http methods, status codes, and percent-encoding to understand how urls are exploited in attacks.
Identify malware dns tactics such as domain generation algorithms and fast flux using logs and dns reputation; mitigate with recursive dns, dns whitelisting, and Alexa top 500 domains.
Identify security events by analyzing packets and protocols with Wireshark, spot unrecognized connections and beaconing, and inspect DNS, Telnet, and FTP traffic for forensics.
Explore flow analysis to inspect network traffic, identify protocols and ports, and detect anomalies with alerts. Use NetFlow, Argus, and Zeke for visualization and reporting.
Identify endpoint behavior using known-good baselines and UEBA, and detect anomalous activity with AI-powered analytics, EPP/EDR, and comprehensive process monitoring.
Explore malware analysis techniques, including fileless malware, droppers, and living off the land with PowerShell and Python, then learn reverse engineering using strings and decompilers.
Learn to identify log sources, analyze event logs, syslog and var/log entries, and use firewall, proxy, and IDS/IPS logs to detect security events and changes with SIEM tools.
Explore impact analysis for security events, using taxonomy-based and impact-based classifications to assess immediate and total costs, scope local vs organizational, and potential reputational damage.
Explore how SIEMs aggregate and normalize security events, using dashboards, widgets, and Kibana to triage incidents, write rules, and enrich data with threat intelligence.
Explore email threats and defenses by analyzing phishing types, recognizing social engineering vectors like spear phishing and business email compromise, and implementing SPF, DKIM, and DMARC to verify sender integrity.
Explore file permissions across Windows and Linux, using icacls and chmod to set read, write, and execute rights, and learn ownership with chown and group settings for secure access control.
Explore blacklisting and whitelisting to control which applications and traffic run in your infrastructure, weigh pros and cons, and apply execution control across endpoints.
Identify firewall configuration concepts and topologies, including a two-firewall DMZ design. Apply ACL-based rules, block martians and bogons, and implement drop vs reject and egress filtering.
Identify DLP basics, classify sensitive data, and enforce policies with alerts and remediation across endpoints and networks, using structured and unstructured data detection.
Explore how network access control uses 802.1X, supplicant and authenticator roles, and health-check policies to grant or restrict network access, including remediation and policy-based controls.
Differentiate blackholes and sinkholes in network security. Blackholes drop traffic using null routing, while sinkholes forward traffic for analysis to identify threats and quarantine infected devices.
Identify and submit suspicious files to vendors or VirusTotal to expand malware signatures, and use standardized naming (CARO, MAEC) and YARA rules to classify and detect malware.
Explore threat hunting by formulating a hypothesis, modeling threats, and profiling actors with their tactics, techniques and procedures to detect indicators of compromise via SIEM and reduce the attack surface.
Automate repetitive tasks with scripting using Bash to parse logs and reduce administrative burden. Explore PowerShell for Windows logon events and note Python, Ruby, and Golang for cross-platform security tooling.
Explore the differences between artificial intelligence, machine learning, and deep learning, including expert systems, data requirements, and how each powers end-point protection and large data sets.
Explore continuous integration, delivery, and deployment, contrast iterative development with traditional approaches, and see how development, test, staging, and production environments support secure, incremental code delivery.
Learn how to communicate security incidents securely and methodically using out-of-band channels, identify who must be informed, comply with GDPR, and prioritize high-value data in incident response.
Explore the six incident response phases from preparation to lessons learned, including identification, containment, eradication, and recovery, with practical planning, escalation, and playbooks.
Identify indicators of compromise across network, host, and applications to triage security incidents. Detect beaconing, bandwidth spikes, rogue devices, and suspicious processes with tools like Wireshark and NetFlow.
Identify, collect, analyze, and report digital evidence using forensically sound methods; maintain chain of custody, hash evidence, and apply order of volatility across memory, disk, and mobile data.
Explore the distinction and overlap between privacy and security, and how data governance, the CIA triad, and regulatory concerns shape safeguards through policies and controls.
Explore non-technical controls basics, including data governance, the data life cycle, and data classification to uphold confidentiality and integrity through purpose limitation, data minimization, and sovereignty.
Explore retention policies and data life-cycle as non-technical controls, and define data ownership roles—owner, steward, custodians, privacy officer—plus ndas, slas, isas, e-discovery, and regulatory compliance.
Explore software-driven technical controls and access controls, geographic access requirements, and encryption across rest, in transit, and in use, with data loss prevention templates.
Explore advanced technical controls for de-identification, data masking, tokenization, and digital rights management. Learn how re-identification risks and data roles protect PII and PHI in large data sets.
Explore how information security risk is identified and managed through a systematized enterprise risk management frame that assesses, monitors, and responds to threats using NIST SP 839 guidance.
Compute risk by analyzing probability and magnitude to derive risk, using asset value and exposure factor to obtain single loss expectancy, then apply ALE to guide controls.
Explore how business impact analysis informs risk decisions by assessing system importance, potential losses, and recovery metrics like MTD, RTO, WRT, and RPO.
Prioritize and communicate risk using context-driven risk evaluation, four response strategies (accept, avoid, mitigate, transfer), ROSI calculations, and risk registers to inform business decisions.
Document compensating controls and train across the risk lifecycle, using a risk register to prioritize investments, and practice through tabletop exercises and red-blue-white team wargaming.
Apply risk management to supply chains by conducting vendor due diligence, ensuring source authenticity, and evaluating depth of the supply chain with trusted foundry concepts for secure hardware.
Discover how security controls strengthen risk management through governance with the NIST framework and COA matrix, covering categories like administrative, managerial, operational, and technical, plus preventative and detective types.
Define the four phases of digital forensics: identification, collection, analysis, and reporting, through policies, procedures, and a code of ethics; emphasize chain of custody and work product retention.
Explore how prescriptive and risk-based frameworks guide security and risk management, and how audits, assessments, compliance and continuous monitoring verify and improve regulatory alignment.
Examine identity and access management governance, including authentication, authorization, auditing, password policies, data ownership and retention, and acceptable use policies to minimize risk.
This course is designed for cybersecurity professionals who want to further their knowledge and skills in detecting and preventing cybersecurity threats.
In this course, you will learn how to perform data analysis and interpret the results to identify and respond to cybersecurity threats. You will also learn how to use various tools and techniques to prevent cybersecurity incidents from occurring.
The course covers the following topics:
1. Threat and Vulnerability Management: This topic covers the identification and mitigation of vulnerabilities and threats, including assessing risk and conducting vulnerability scans.
2. Software and Systems Security: This topic covers the security of software and systems, including secure coding practices, software security testing, and secure network protocols.
3. Security Operations and Monitoring: This topic covers security operations and monitoring, including incident response, threat hunting, and security information and event management (SIEM).
4. Incident Response: This topic covers the steps involved in responding to security incidents, including identifying and containing the incident, analyzing and remediating the impact, and implementing improvements to prevent future incidents.
5. Compliance and Assessment: This topic covers compliance and assessment, including regulatory compliance, risk management, and security audits.
Whether you are new to the cybersecurity field or an experienced professional looking to enhance your skills, this course will provide you with the knowledge and skills you need to succeed. So, let's get started!
"This course qualifies for CompTIA continuing education units (CEUs)."
Available CEUs* for this Course Series : 25
By completing this course series, you can earn up to 25 CEUs.
(*CEUs are entirely dependent on the organization you are applying)