
Meet John Boog, a seasoned technical trainer and retired army communications and signal soldier, introducing the CompTIA CySA+ course and his IT certification expertise.
Explore the CompTIA CySA+ CS0-002 exam, a workforce certification for cybersecurity analysts focused on threat detection and continuous monitoring across five domains.
Learn practical test-taking strategies for the CompTIA CySA+ CS0-002 exam, including answering exactly what the question asks, and prioritizing human safety, laws, and business needs, and skipping performance-based questions first.
Explain the importance of threat data and intelligence, including open vs closed source sources, confidence levels, indicators of compromise, and the intelligence cycle guiding sector ISACs.
Apply threat intelligence to support organizational security by using attack frameworks such as the minor attack framework, the diamond model, and cyber kill chain to map adversaries, capabilities, and infrastructure.
Explore vulnerability management: identify assets and criticality, perform vulnerability scans (passive vs active), understand scan results, remediate with baselines, patching, testing, backouts, automation, and hardening to reduce attack surface.
Explore compensating controls, risk appetite, and regulatory considerations, and learn vulnerability scanning and remediation strategies, including governance and service level agreements.
Analyze outputs from common vulnerability assessment tools such as OWASP Zap, Nessus, OpenVAS, and Qualys, and interpret scan results, static vs dynamic analysis, and enumeration findings.
Analyze threats and vulnerabilities in embedded systems, real-time operating systems, system on a chip. Assess risks across IoT devices, BYOD, MDM, FPGA, and SCADA with Modbus and CAN bus.
Explore cloud service models—SaaS, PaaS, IaaS, and serverless—along with deployment types and infrastructure as code, highlighting security and governance concerns.
Analyze how to mitigate attacks and software vulnerabilities by applying input validation, parameterized queries, and patch management, while recognizing SQL injection, buffer overflows, and privilege escalation.
Protect web sessions from hijacking by encrypting data, randomizing session ids, and re-authenticating regularly; guard against rootkits and cross-site scripting with hardening and input validation.
Evaluate cloud versus on-premises deployments to balance cost, convenience, and control while securing data and access. Implement defense in depth with segmentation, DMZs, bastion hosts, jump servers, and policy-driven access.
Examine software defined networking, including controllers, data plane and application plane, and how it enables dynamic infrastructure management; explore VPNs, VDI, containerization, CASB, and honeypots as security solutions.
Examine identity and access management, including privilege management, multi-factor authentication, SSO and federated identity, RBAC/ABAC/MAC, and the importance of change management, auditing, and proactive monitoring to prevent privilege creep.
Define software assurance per National Information Assurance Glossary and outline how secure development life cycle practices, devsecops, and testing across mobile, embedded, and web platforms ensure safety and functionality.
Explain hardware root of trust, TPMs and remote attestation, EFI/secure boot, measured boot, secure enclaves, and anti tampering within a zero-trust hardware security model.
Analyze security monitoring data with heuristics and signatures. Explore sandbox malware analysis, endpoint monitoring, file integrity checks, and user and entity behavior analytics to detect anomalous activity and guide remediation.
Analyze incident impact and costs, distinguishing immediate versus long-term effects, while leveraging a SIEM to correlate events, compare agent-based and agentless deployments, and use queries and regex to surface logs.
Analyze security monitoring data with regex patterns to locate private IP addresses and port numbers of 1000 or greater, and assess email threats using DKIM, SPF, DMARC, and header analysis.
Explore how to implement configuration changes to Linux and Windows controls to improve security, including file permissions, chmod, setuid/setgid, ownership, and firewall ACLs with implicit and explicit denies.
Explore how firewalls handle packets, with drop or reject decisions, along with ingress and egress filtering, and learn core concepts of idps, dlp, edr, and nac.
Establish a hypothesis, profile threat actors and their tactics, techniques and procedures, and pursue analytic actions to drive proactive threat hunting, reducing risk and improving detection.
Explain the importance of the incident response process. Outline a communication plan, data breach disclosure considerations, reporting requirements, and coordination with leadership, legal, HR, and PR.
Learn how to build and apply an incident response program, covering policy, roles, preparation, detection and analysis, containment, eradication, recovery, and post-incident reporting.
Examine network indicators of compromise, including bandwidth baselines, unusual traffic, rogue devices, and scans on non-standard ports, plus host signs like memory use and data exfiltration indicators.
Identify digital evidence, secure the scene, collect and analyze copies with proper tools, and report findings according to chain-of-custody, order of volatility, and legal holds.
Explore the distinction between privacy and security, and learn data classification, retention, and data owner, custodian, and steward roles to safeguard privacy while complying with GDPR, HIPAA, and SOX.
Apply enterprise risk management by identifying threats and vulnerabilities affecting assets, evaluating probability and impact, and using qualitative and quantitative assessments to prioritize controls and communicate business risk.
Examine mitigating organizational risk by applying metrics such as MTD, RTO, and RPO, managing service levels, vendor due diligence, tabletop and pen testing, and compensating controls.
Explore how frameworks guide enterprise security, comparing prescriptive and risk-based approaches, and examine policies, procedures, data ownership, and password controls.
Learn how policies, procedures, and continuous monitoring support data retention, account management, least privilege, and audits to ensure regulatory compliance.
Explore threat and vulnerability management, intelligence gathering, IOC concepts, and threat frameworks (diamond model, minor attack framework); cover cloud security, incident response, and risk compliance.
Practice review questions for the CompTIA CySA+ CS0-002 cover live forensic imaging, double blind tests, VDI, SQL injections, cross-site scripting, mobile security, honeypots, directory traversal, risk and incident response.
Master exam readiness for the CompTIA CySA+ CS0-002 by building dump sheets, understanding the whys of questions, and optimizing study, rest, and test-time strategies.
This CompTIA training certification course taught by Vision Training Systems covers applied behavioral analytics to networks and devices with the intention to prevent, detect, and combat cybersecurity threats via continuous security monitoring. The CompTIA CySA+ certification, earned after passing the CS0-002 exam, validates an IT professional’s ability to proactively defend and continuously improve the security of an organization. The course is intended for Security analysts at a Tier II level, Intermediate/mid-career cybersecurity specialists, Students holding a DoD IAT Level II or CSSP position, CompTIA Network+ or CompTIA Security+ certification holders wanting to take that next step, or anyone else wanting to expand their skillset and knowledge.
As attackers have learned to evade traditional signature-based solutions such as firewalls and anti-virus software, an analytics-based approach within the IT security industry is increasingly important for organizations. Behavioral analytics in regards to networks helps to improve the overall state of security through identifying and combating malware and advanced persistent threats (APTs), resulting in enhanced threat visibility across a broad attack surface.
The CompTIA Cybersecurity Analyst (CySA+) certification verifies that successful candidates have the knowledge and skills required to leverage intelligence and threat detection techniques, analyze and interpret data, identify and address vulnerabilities, suggest preventative measures, and effectively respond to and recover from incidents.
You will learn to leverage intelligence, and threat detection techniques, to analyze and interpret data, to identify and address vulnerabilities, to suggest preventative measures, and to effectively respond to and recover from incidents.
This CompTIA training course reviews topics for the CS0-002 version of the CySA+ exam, which became the only version available as of October 22, 2020. It does not currently have a retirement date, but an exam version is typically active for three years.