
Explore security operations, incident response and vulnerability management, and master reporting and communication while preparing for the CompTIA CySA+ exam with multiple choice and performance-based questions.
Learn how time synchronization with NTP keeps server clocks aligned for accurate event timelines and incident response. Explore log ingestion concepts and syslog levels: fatal, error, warn, info, debug, trace.
Explore Windows registry concepts and hive structure, and compare Windows and Linux file structures. Apply system hardening, process monitoring, and architecture basics to defend and troubleshoot systems.
Discover serverless infrastructure, virtualization, and containerization concepts, including bare metal and hosted hypervisors, and practical Docker techniques with Docker Hub and HTTP servers.
Explore identity and access management concepts like MFA, SSO, federation, PAM, and CASB, emphasizing least privilege, secret rotation, and securing cloud services with visibility, compliance, data security, and threat protection.
Explore common encryption concepts through PKI, including certificate management systems, CA, RA, VA, and certificates. Learn about self-signed certificates, CA services, and ssl inspection in encrypted traffic.
Explore data loss prevention, PII, and cardholder data protection through encryption, obfuscation, and strict key management within PCI DSS guidelines to minimize storage, restrict access, and secure data.
Explore common network architectures—on-prem, cloud, and hybrid—and examine how network segmentation and zero trust, with secure access edge (sassy) concepts, shape modern networks.
Identify malicious network activity by monitoring bandwidth consumption, beaconing, irregular peer-to-peer traffic, rogue devices, and unexpected ports; use asset discovery, scans, and SIEM alerts.
Learn to detect malicious host activity by monitoring processor, memory, storage, network usage, and unauthorized software, suspicious processes, privilege changes, and data exfiltration indicators.
Identify anomalous application activity by establishing baselines and using tools like Wireshark and netstat to detect new accounts, unusual output, outbound communications, and service interruptions, triggering incident response.
Explore how social engineering attacks drive malicious activity, focusing on phishing and obfuscated links arising from typosquatting and URL encoding, and learn vigilant practices to avoid clicking dangerous prompts.
Explore packet capture tools, focusing on Wireshark and tcpdump, to capture, filter, and inspect traffic using IP, port, protocol, and flags with logical operators.
Explore log analysis tools, including SIEM and syslog, for aggregating and alerting on security events, and see how SOWAR augments these with orchestration and automation.
Learn how endpoint detection and response uses machine learning to detect sophisticated threats beyond traditional antivirus, establish baselines with agent data, and automate alerts, responses, and remediation.
Explore how DNS and IP reputation tools assess domain and IP trust. Use real-time threat data and abuse databases to block malicious sites and spam.
Learn to analyze files with strings and hashing, verify integrity with MD5 and SHA-256, and use VirusTotal to assess malware risk.
Explore sandboxing tools to safely analyze potential malware, using Joe Sandbox or Cuckoo Sandbox, and learn to configure architectures, samples, and execution.
Learn how to analyze emails using headers, links, and attachments, and apply SPF, DKIM, and DMARC to verify sender authenticity and protect against spoofing.
Explore user and entity behavior analytics (UEBA) to detect anomalous activity, establish baselines, and generate alerts for compromised credentials and insider threats, using tools like Splunk and Microsoft Sentinel.
Learn scripting and programming basics in Python, PowerShell, and shell scripts; understand JSON and XML data exchange, regex, and their role in automating admin tasks and security.
Learn threat actor types from script kitties to nation-state APTs, including insider threats (intentional and unintentional), hacktivists, organized crime, and supply chain attackers.
Explore TTPs—tactics, techniques, and procedures—from high-level attacker goals to specific methods, and map them with the MITRE ATT&CK framework for threat modeling and mitigations and detections.
Explore CTI confidence levels by examining strategic, tactical, and operational CTI, and assess timeliness, relevancy, and accuracy to guide threat intel feeds and defense decisions.
Explore open and closed CTI sources—from social media and blogs to government advisories and paid feeds—to curate threat intelligence for your organization or environments.
Learn how CTI sharing improves attribution, vulnerability management, and detection, using STIX and TAXII, hub-and-spoke and peer-to-peer models, plus Yara and Sigma.
Shorten breach discovery by hunting for indicators of compromise. Collect and analyze IOCs and PCAPs to map the attack to MITRE ATT&CK and enhance defenses.
Identify tasks suitable for automation by focusing on repeatable, high-volume, error-prone, and monotonous workflows with homogeneous data, then coordinate goals, requirements, and best practices to implement tailored automation.
Streamlining operations through automation and orchestration, using a SOAR approach to centralize tools, enrich threat intelligence with context, and minimize human engagement to speed detection and prioritization.
Learn how to integrate tools into security operations using APIs, webhooks, plugins, and a single pane of glass, with VirusTotal API examples and automation through curl and Python.
Discover and map network assets with nmap, zenmap, angry IP scanner, and maltego to build an asset inventory and verify device types, OS, and ports.
Explore vulnerability scanning types and key considerations, including scheduling, regulatory and sensitivity levels, internal vs external scans, agent vs agentless, credentialed vs non-credentialed, and static vs dynamic approaches.
Explore vulnerability scanning frameworks such as PCI DSS, CIS benchmarks, OWASP, and ISO 27,001, and learn how they guide vulnerability management, hardening, and access controls.
Analyze vulnerability scanner output to interpret results from web application scanners and tools like Burp Suite, OWASP ZAP, NIC2, Arachne, Nessus, and OpenVoz.
Explore the CVSS scoring system, including base metrics, exploitability metrics, and impact metrics. Learn how attack vectors like network, adjacent, local, and physical shape a 9.8 critical base score.
Prioritize vulnerabilities by validating scan results, weighing true positives, false positives, true negatives, and false negatives, and applying context awareness, exploitability, weaponization, asset value, and zero-day risk.
Master mitigations for software vulnerabilities, including cross-site scripting protection via input sanitization and output encoding, memory safety with address space layout randomization and canaries, and defenses against injection and csrf.
Discover the software development lifecycle and security's role across requirements and artifacts, functional and non-functional needs, security requirements, development, testing, and retirement in agile settings.
Threat modeling integrates with pen testing to identify attack surface, vectors, and impacts, using stride and pasta frameworks to assess risk and guide incident response and defenses.
Explore compensating controls, including preventive, managerial, operational, technical, detective, and responsive types, with examples like multi-factor authentication and backups, plus hands-on Cisco DevNet DNA Center sandboxes.
Master patching, configuration management, maintenance windows, and exceptions to protect systems; test patches, validate deployments, enable rollback, and manage personal devices with Intune.
Identify risks and assets to inform incident response, then apply the four risk management options—avoid, transfer, mitigate, or accept—while continuing monitoring and logging.
Explore policies, governance, and service level objectives (SLOs), including their ties to SLAs, SLIs, and BLOs, and examine risk management and error budgets.
Prioritize security incidents by evaluating functional impact, information and data impact, and recoverability, then follow discrete escalation procedures, engaging cloud support paths in AWS, Google, Microsoft, and IBM.
Learn attack surface management by discovering exposed edge devices, reducing unneeded services, and using bug bounties and pen testing to harden cloud and on-premises defenses.
Identify six secure coding practices, including input validation, output encoding, session management, authentication, and parameterized queries, and examine data protection at rest, in transit, and in use with cloud tools.
Explore attack methodology frameworks, including the cyber kill chain and MITRE attack framework, tracing reconnaissance, weaponization, exploitation, installation, and command and control, plus the Diamond model and Colonial Pipeline case.
Explore detection and analysis in the incident response lifecycle's first two phases, identify indicators of compromise from network and host activity, and learn evidence collection and log analysis with Splunk.
Master containment, eradication, and recovery in incident response by sizing scope, applying segmentation, isolating affected systems, rebuilding with evidence gathering, and ensuring business continuity.
Prepare for breaches by training on the incident response plan and drills. Secure funding for tools, playbooks, and tabletop workshops, guided by NIST.
Explore post-incident activity, including forensic analysis and digital forensics, root cause analysis guided by NIST standards, and learn to craft lessons learned reports and audience-tailored communications.
Communicate vulnerability management findings clearly by tailoring reports to each audience, prioritize risks with a scoring matrix, and guide remediation through configuration and patch management.
Learn incident response metrics and KPIs, including mean times to detect, identify, respond, contain, remediate, and recover, and manage alert fatigue for effective containment and recovery.
Understand how to communicate compliance reporting as evidence of adherence to regulations, standards, and obligations, tailoring scope and controls, and monitor and validate ongoing compliance.
Identify inhibitors to remediation, including SLAs and MOUs, leadership pushback, compensating controls, degraded functionality, and legacy or air-gapped systems, and learn how to prioritize patch and vulnerability management decisions.
Communicate incident response reports by identifying key stakeholders, using playbooks and executive summaries, and detailing the five Ws, timelines, recommendations, evidence, and chain of custody for regulatory obligations.
Learn how post-incident root cause analysis identifies vulnerabilities and contributing factors, maps kill chain timelines, and deploys controls to prevent reoccurrence and reduce impact.
Communicate vulnerability metrics and KPIs using trend analysis, OWASP top 10, CVEs, and zero-day risk insights. Highlight the role of SLOs in service level agreements for measurable reliability.
The CompTIA Cybersecurity Analyst (CySA+) certification is designed to validate the skills necessary for cybersecurity analysts. This course prepares candidates for the exam by covering a comprehensive range of topics critical to the role:
1. Threat Intelligence: Understanding and utilizing threat intelligence to proactively defend against potential threats.
2. Vulnerability Management: Identifying, classifying, prioritizing, and mitigating vulnerabilities to enhance overall security posture.
3. Incident Response: Developing and implementing incident response plans to effectively respond to security incidents.
4. Analysing Security Logs and Events: Monitoring and analyzing security logs and events to detect and respond to suspicious activities.
5. Security Incident Identification and Response: Recognizing indicators of compromise (IoCs) and responding promptly to security incidents to minimize impact.
6. Communication of Security Findings: Articulating security findings, both technical and non-technical, to stakeholders for informed decision-making.
The CySA+ certification is highly regarded in the industry and provides professionals with the validation needed to advance their careers in cybersecurity. It equips them with practical skills and knowledge essential for roles such as cybersecurity analyst, security operations center (SOC) analyst, and vulnerability analyst, among others.
This course aims to comprehensively prepare individuals for the CySA+ exam, ensuring they are proficient in analysing security data, identifying vulnerabilities, and responding effectively to cybersecurity incidents. It emphasizes hands-on experience and practical application of cybersecurity principles in real-world scenarios.