CompTIA Cybersecurity Analyst (CySA+)

Level: Advanced

Build Practical Threat Detection & Security Analysis Skills
Learn to Manage Vulnerabilities & Respond to Cyber Incidents
Prepare for the CompTIA Cybersecurity Analyst (CySA+) Certification
Official CompTIA Course Materials & Exam Included
Exam Pass Guarantee Included*
Welsh Government Funding Accepted
Get this course for FREE with PLA Digital Funding!

Course Overview

Duration: 5 Days (9am-5pm) Accredited: Yes Exams: Included Funding: PLA, PLA Digital, ReAct Type: Classroom, Online, Onsite, Virtual Company group booking discount available
This CompTIA Cybersecurity Analyst (CySA+) course develops the skills needed to detect, investigate and respond to cybersecurity threats across networks, endpoints and cloud environments. Based on CySA+ V4, delegates will explore security monitoring, vulnerability management, incident response and reporting. The course also introduces the use of artificial intelligence in security [...]

This CompTIA Cybersecurity Analyst (CySA+) course develops the skills needed to detect, investigate and respond to cybersecurity threats across networks, endpoints and cloud environments.

Based on CySA+ V4, delegates will explore security monitoring, vulnerability management, incident response and reporting. The course also introduces the use of artificial intelligence in security operations, including its risks and governance considerations.

This five-day course prepares delegates for the CompTIA CySA+ CS0-004 examination, which is taken after the training.

Target Audience

This course is suitable for IT and cybersecurity professionals working in, or progressing towards, roles including:

  • Security analyst
  • Security operations centre (SOC) analyst
  • Incident response analyst
  • Vulnerability management analyst
  • Security engineer

By the End of This Course, You Will Be Able To

  • Investigate suspicious activity across networks, endpoints and cloud environments.
  • Analyse data using security information and event management (SIEM) and endpoint detection and response (EDR) tools.
  • Use threat intelligence to support threat hunting.
  • Assess vulnerabilities and prioritise remediation according to risk.
  • Apply structured incident response techniques.
  • Explain how automation and AI support security operations.
  • Communicate findings through reports, dashboards and incident reviews.
  • Prepare for the CompTIA CySA+ V4 examination.
This CompTIA Cybersecurity Analyst (CySA+) course develops the skills needed to detect, investigate and respond to cybersecurity threats across networks, endpoints and cloud environments. Based on CySA+ V4, delegates will explore security monitoring, vulnerability management, incident response and reporting. The course also introduces the use of artificial intelligence in security [...]

This CompTIA Cybersecurity Analyst (CySA+) course develops the skills needed to detect, investigate and respond to cybersecurity threats across networks, endpoints and cloud environments.

Based on CySA+ V4, delegates will explore security monitoring, vulnerability management, incident response and reporting. The course also introduces the use of artificial intelligence in security operations, including its risks and governance considerations.

This five-day course prepares delegates for the CompTIA CySA+ CS0-004 examination, which is taken after the training.

Target Audience

This course is suitable for IT and cybersecurity professionals working in, or progressing towards, roles including:

  • Security analyst
  • Security operations centre (SOC) analyst
  • Incident response analyst
  • Vulnerability management analyst
  • Security engineer

By the End of This Course, You Will Be Able To

  • Investigate suspicious activity across networks, endpoints and cloud environments.
  • Analyse data using security information and event management (SIEM) and endpoint detection and response (EDR) tools.
  • Use threat intelligence to support threat hunting.
  • Assess vulnerabilities and prioritise remediation according to risk.
  • Apply structured incident response techniques.
  • Explain how automation and AI support security operations.
  • Communicate findings through reports, dashboards and incident reviews.
  • Prepare for the CompTIA CySA+ V4 examination.

CompTIA Cybersecurity Analyst (CySA+)

Lesson 1: Explaining the Importance of Security Controls and Security Intelligence

  • Topic 1A: Identify Security Control Types
  • Topic 1B: Explain the Importance of Threat Data and Intelligence

Lesson 2: Utilising Threat Data and Intelligence

  • Topic 2A: Classify Threats and Threat Actor Types
  • Topic 2B: Utilise Attack Frameworks and Indicator Management
  • Topic 2C: Utilise Threat Modelling and Hunting Methodologies

Lesson 3: Analysing Security Monitoring Data

  • Topic 3A: Analyse Network Monitoring Output
  • Topic 3B: Analyse Appliance Monitoring Output
  • Topic 3C: Analyse Endpoint Monitoring Output
  • Topic 3D: Analyse Email Monitoring Output

Lesson 4: Collecting and Querying Security Monitoring Data

  • Topic 4A: Configure Log Review and SIEM Tools
  • Topic 4B: Analyse and Query Logs and SIEM Data

Lesson 5: Utilising Digital Forensics and Indicator Analysis Techniques

  • Topic 5A: Identify Digital Forensics Techniques
  • Topic 5B: Analyse Network-related IoCs
  • Topic 5C: Analyse Host-related IoCs
  • Topic 5D: Analyse Application-Related IoCs
  • Topic 5E: Analyse Lateral Movement and Pivot IoCs

Lesson 6: Applying Incident Response Procedures

  • Topic 6A: Explain Incident Response Processes
  • Topic 6B: Apply Detection and Containment Processes
  • Topic 6C: Apply Eradication, Recovery, and Post‑Incident Processes

Lesson 7: Applying Risk Mitigation and Security Frameworks

  • Topic 7A: Apply Risk Identification, Calculation, and Prioritisation Processes
  • Topic 7B: Explain Frameworks, Policies, and Procedures

Lesson 8: Performing Vulnerability Management

  • Topic 8A: Analyse Output from Enumeration Tools
  • Topic 8B: Configure Infrastructure Vulnerability Scanning Parameters
  • Topic 8C: Analyse Output from Infrastructure Vulnerability Scanners
  • Topic 8D: Mitigate Vulnerability Issues

Lesson 9: Applying Security Solutions for Infrastructure Management

  • Topic 9A: Apply Identity and Access Management Security Solutions
  • Topic 9B: Apply Network Architecture and Segmentation Security Solutions
  • Topic 9C: Explain Hardware Assurance Best Practices
  • Topic 9D: Explain Vulnerabilities Associated with Specialised Technology

Lesson 10: Understanding Data Privacy and Protection

  • Topic 10A: Identify Non-Technical Data and Privacy Controls
  • Topic 10B: Identify Technical Data and Privacy Controls

Lesson 11: Applying Security Solutions for Software Assurance

  • Topic 11A: Mitigate Software Vulnerabilities and Attacks
  • Topic 11B: Mitigate Web Application Vulnerabilities and Attacks
  • Topic 11C: Analyse Output from Application Assessments

Lesson 12: Applying Security Solutions for Cloud and Automation

  • Topic 12A: Identify Cloud Service and Deployment Model Vulnerabilities
  • Topic 12B: Explain Service-Oriented Architecture
  • Topic 12C: Analyse Output from Cloud Infrastructure Assessment Tools
  • Topic 12D: Compare Automation Concepts and Technologies

CompTIA Cybersecurity Analyst (CySA+)

Lesson 1: Explaining the Importance of Security Controls and Security Intelligence

  • Topic 1A: Identify Security Control Types
  • Topic 1B: Explain the Importance of Threat Data and Intelligence

Lesson 2: Utilising Threat Data and Intelligence

  • Topic 2A: Classify Threats and Threat Actor Types
  • Topic 2B: Utilise Attack Frameworks and Indicator Management
  • Topic 2C: Utilise Threat Modelling and Hunting Methodologies

Lesson 3: Analysing Security Monitoring Data

  • Topic 3A: Analyse Network Monitoring Output
  • Topic 3B: Analyse Appliance Monitoring Output
  • Topic 3C: Analyse Endpoint Monitoring Output
  • Topic 3D: Analyse Email Monitoring Output

Lesson 4: Collecting and Querying Security Monitoring Data

  • Topic 4A: Configure Log Review and SIEM Tools
  • Topic 4B: Analyse and Query Logs and SIEM Data

Lesson 5: Utilising Digital Forensics and Indicator Analysis Techniques

  • Topic 5A: Identify Digital Forensics Techniques
  • Topic 5B: Analyse Network-related IoCs
  • Topic 5C: Analyse Host-related IoCs
  • Topic 5D: Analyse Application-Related IoCs
  • Topic 5E: Analyse Lateral Movement and Pivot IoCs

Lesson 6: Applying Incident Response Procedures

  • Topic 6A: Explain Incident Response Processes
  • Topic 6B: Apply Detection and Containment Processes
  • Topic 6C: Apply Eradication, Recovery, and Post‑Incident Processes

Lesson 7: Applying Risk Mitigation and Security Frameworks

  • Topic 7A: Apply Risk Identification, Calculation, and Prioritisation Processes
  • Topic 7B: Explain Frameworks, Policies, and Procedures

Lesson 8: Performing Vulnerability Management

  • Topic 8A: Analyse Output from Enumeration Tools
  • Topic 8B: Configure Infrastructure Vulnerability Scanning Parameters
  • Topic 8C: Analyse Output from Infrastructure Vulnerability Scanners
  • Topic 8D: Mitigate Vulnerability Issues

Lesson 9: Applying Security Solutions for Infrastructure Management

  • Topic 9A: Apply Identity and Access Management Security Solutions
  • Topic 9B: Apply Network Architecture and Segmentation Security Solutions
  • Topic 9C: Explain Hardware Assurance Best Practices
  • Topic 9D: Explain Vulnerabilities Associated with Specialised Technology

Lesson 10: Understanding Data Privacy and Protection

  • Topic 10A: Identify Non-Technical Data and Privacy Controls
  • Topic 10B: Identify Technical Data and Privacy Controls

Lesson 11: Applying Security Solutions for Software Assurance

  • Topic 11A: Mitigate Software Vulnerabilities and Attacks
  • Topic 11B: Mitigate Web Application Vulnerabilities and Attacks
  • Topic 11C: Analyse Output from Application Assessments

Lesson 12: Applying Security Solutions for Cloud and Automation

  • Topic 12A: Identify Cloud Service and Deployment Model Vulnerabilities
  • Topic 12B: Explain Service-Oriented Architecture
  • Topic 12C: Analyse Output from Cloud Infrastructure Assessment Tools
  • Topic 12D: Compare Automation Concepts and Technologies
  • Examination: CompTIA Cybersecurity Analyst (CySA+)
  • Version: V4
  • Examination code: CS0-004
  • Duration: 165 minutes
  • Number of questions: Maximum of 85
  • Question format: Multiple-choice and performance-based questions
  • Passing score: 750 on a scale of 100–900
  • Open book: No
  • Delivery: Online proctored examination or at a Pearson VUE test centre

 

  • Examination: CompTIA Cybersecurity Analyst (CySA+)
  • Version: V4
  • Examination code: CS0-004
  • Duration: 165 minutes
  • Number of questions: Maximum of 85
  • Question format: Multiple-choice and performance-based questions
  • Passing score: 750 on a scale of 100–900
  • Open book: No
  • Delivery: Online proctored examination or at a Pearson VUE test centre

 

  • Five days of instructor-led training and exam preparation delivered by an accredited CompTIA trainer.
  • Official CompTIA courseware and learning materials.
  • CompTIA CySA+ certification examination voucher included. Examination vouchers are usually valid for up to 12 months from the date of issue; however, CompTIA requirements or funding rules for schemes such as PLA, ReAct or other government-funded programmes may require learners to sit their examination within a shorter timeframe. Learners must meet the examination deadline confirmed by NILC.
  • Exam Pass Guarantee – if you do not pass the examination after attending the course, you can retake the same training with NILC at no additional cost. You will only need to pay the examination fee charged by the exam provider. Applies to instructor-led courses only.
  • Five days of instructor-led training and exam preparation delivered by an accredited CompTIA trainer.
  • Official CompTIA courseware and learning materials.
  • CompTIA CySA+ certification examination voucher included. Examination vouchers are usually valid for up to 12 months from the date of issue; however, CompTIA requirements or funding rules for schemes such as PLA, ReAct or other government-funded programmes may require learners to sit their examination within a shorter timeframe. Learners must meet the examination deadline confirmed by NILC.
  • Exam Pass Guarantee – if you do not pass the examination after attending the course, you can retake the same training with NILC at no additional cost. You will only need to pay the examination fee charged by the exam provider. Applies to instructor-led courses only.

Delegates should hold CompTIA Network+ and Security+ certifications or have equivalent knowledge.

CompTIA recommends about four years of experience as a security operations centre (SOC) analyst or vulnerability analyst. This is recommended experience, not a requirement to hold another certification.

Delegates should hold CompTIA Network+ and Security+ certifications or have equivalent knowledge.

CompTIA recommends about four years of experience as a security operations centre (SOC) analyst or vulnerability analyst. This is recommended experience, not a requirement to hold another certification.

How does NILC’s Exam Pass Guarantee work?

If you do not pass after attending NILC’s instructor-led CySA+ course, you can repeat the same training free of charge. You will still need to pay the examination provider’s resit fee.

Who is the CompTIA CySA+ V4 course suitable for?

CySA+ V4 is suitable for cybersecurity professionals working in security operations, vulnerability management and incident response, including Security Operations Centre analysts and vulnerability analysts.

What experience should I have before taking CySA+ V4?

CompTIA recommends about four years of experience as a SOC analyst or vulnerability analyst. NILC also recommends Network+ and Security+ certifications or equivalent knowledge. These are recommended foundations for the training.

View all FAQs

How does NILC’s Exam Pass Guarantee work?

If you do not pass after attending NILC’s instructor-led CySA+ course, you can repeat the same training free of charge. You will still need to pay the examination provider’s resit fee.

Who is the CompTIA CySA+ V4 course suitable for?

CySA+ V4 is suitable for cybersecurity professionals working in security operations, vulnerability management and incident response, including Security Operations Centre analysts and vulnerability analysts.

What experience should I have before taking CySA+ V4?

CompTIA recommends about four years of experience as a SOC analyst or vulnerability analyst. NILC also recommends Network+ and Security+ certifications or equivalent knowledge. These are recommended foundations for the training.

View all FAQs

Dates & Prices

Upcoming Courses
Live Instructor-Led Virtual
Spaces: Available Start Date: Mon 12 October 2026
£2,595.00 excl. VAT

Can't find the course dates, location or delivery type you are looking for?

Fill out the request dates form above and we'll try our best to accommodate or contact us directly.

"*" indicates required fields

Name*
Number of Delegates*
Course Delivery Format*

How we deliver our courses

Virtual

Our virtual courses allow you to access live instructor-led training from the same expert instructors that deliver our classroom courses, without leaving the comfort of your home or office. All virtual courses are fully interactive, and learners can communicate with their trainer and peers at any time.

Many of our virtual courses are also recorded, so you can recap over the content you learnt as many time as you wish.

Find out more about Virtual learning

Classroom

Our classroom courses allow you to learn and interact face-to-face with our expert instructors in a comfortable and modern training environment. All of our classroom based courses take place at NILC centers, or high quality training facilities, and include all required IT and physical equipment.

We also limit our class sizes to help promote better discussions and to ensure your learning experience is comfortable as possible.

Find out more about Classroom learning

Onsite

Save time and hassle by arranging for one of our expert instructors to come to you. Our onsite courses allow you to learn in a location of your choosing, and you can train as many or as few people as you want – from a single person or team to whole departments. We can also fully customize the course content to the specific requirements of your business or project.

We offer onsite courses throughout the UK and it can be a great team building opportunity for colleagues to come together, bond and discuss.

Find out more about Onsite learning

Online

Our Online Self Paced courses allow you to learn new skills from our expert instructors, in your own time and at your own pace. Our flexible online learning platform allows you to access content on your computer, tablet or mobile device, whether you’re on the move or at home. All our online courses come with immediate access and you can start learning straight away, from any internet enabled compatible device.

We also offer online email support from our expert instructors, so they’re always on hand and happy to help you with any questions which may arise.

Find out more about Online learning

Why choose NILC for your training?

Award-Winning Training with Industry-Leading Customer Satisfaction

Trusted Training Partner by Colleges, Government Organisations and Businesses

UK-Based Trainers with Real-World Industry Experience

Family-Run Business with Customer Service at Its Core

Rated Excellent on Trustpilot with 950+ Customer Reviews

Our learners rate us 'Excellent' on Trustpilot

Frequently Asked Questions

If you do not pass after attending NILC’s instructor-led CySA+ course, you can repeat the same training free of charge. You will still need to pay the examination provider’s resit fee.

CySA+ V4 is suitable for cybersecurity professionals working in security operations, vulnerability management and incident response, including Security Operations Centre analysts and vulnerability analysts.

CompTIA recommends about four years of experience as a SOC analyst or vulnerability analyst. NILC also recommends Network+ and Security+ certifications or equivalent knowledge. These are recommended foundations for the training.

CySA+ builds on existing cybersecurity knowledge and practical experience. Learners new to IT or security should develop their networking and security foundations before undertaking this analyst-focused course.

The four areas are security operations, vulnerability management, incident response and management, and reporting and communication. You will develop skills in investigation, risk-based prioritisation and communicating findings.

Yes. V4 includes AI use cases, risks, and governance in security operations, along with automation and investigation of suspicious activity across cloud, endpoint, network, and identity environments.

Yes. Topics include monitoring with SIEM and EDR tools, threat hunting, incident triage, evidence handling, containment, recovery and post-incident reporting.

The V4 examination, CS0-004, lasts 165 minutes and includes up to 85 questions. The passing score is 750 on a 100–900 scale.

NILC offers classroom, live virtual and onsite training. Eligible learners may qualify for PLA, PLA Digital or ReAct+ funding. Contact NILC to confirm eligibility, dates and V4 availability.

Frequently Asked Questions

If you do not pass after attending NILC’s instructor-led CySA+ course, you can repeat the same training free of charge. You will still need to pay the examination provider’s resit fee.

CySA+ V4 is suitable for cybersecurity professionals working in security operations, vulnerability management and incident response, including Security Operations Centre analysts and vulnerability analysts.

CompTIA recommends about four years of experience as a SOC analyst or vulnerability analyst. NILC also recommends Network+ and Security+ certifications or equivalent knowledge. These are recommended foundations for the training.

CySA+ builds on existing cybersecurity knowledge and practical experience. Learners new to IT or security should develop their networking and security foundations before undertaking this analyst-focused course.

The four areas are security operations, vulnerability management, incident response and management, and reporting and communication. You will develop skills in investigation, risk-based prioritisation and communicating findings.

Yes. V4 includes AI use cases, risks, and governance in security operations, along with automation and investigation of suspicious activity across cloud, endpoint, network, and identity environments.

Yes. Topics include monitoring with SIEM and EDR tools, threat hunting, incident triage, evidence handling, containment, recovery and post-incident reporting.

The V4 examination, CS0-004, lasts 165 minutes and includes up to 85 questions. The passing score is 750 on a 100–900 scale.

NILC offers classroom, live virtual and onsite training. Eligible learners may qualify for PLA, PLA Digital or ReAct+ funding. Contact NILC to confirm eligibility, dates and V4 availability.

Trusted By

0