4,598 $−459 $4,139 $
What this module delivers.
How the training runs
- Method
- Four exam domains along the incident timeline
- Basis
- Official CompTIA exam objectives
- Outcome
- Exam at Pearson VUE, fee not included
Dates & booking
Choose a date that fits
1 dates
Sessions with this symbol offer up to 25% group discount. Click “Details & Registration” to learn more.
No dates match this selection.
Dates are still available. Reset the filters to see them.
Fit
Who this module is designed for
Typical roles
- You assess alerts from monitoring systems and decide what counts as an incident.
- You prioritise vulnerabilities and justify which get closed first.
- You report findings to both engineering and management in the same week.
Prerequisites
No prerequisites
You can start right away. What you need: English, because CS0-004 is so far only offered in English. Helpful: security fundamentals at CompTIA Security+ level, around four years of practice in analysis, monitoring or vulnerability management.
Consider instead CompTIA Security+ · CompTIA - Security+ (Plus) Certification Fits better if you want to place security first, before assessing alerts daily.
Curriculum
CompTIA CySA+ Curriculum in Detail
The course follows the four CS0-004 exam domains along the course of an incident: first day-to-day security operations, then vulnerability management, then the response to a concrete incident, and finally the reports others decide from.
01Security operations
At 34 percent the largest exam domain, and the basis for everything after it.
- Reading system components and network architecture from a detection viewpoint
- Analysing log, network and endpoint data as indicators
- Translating threat intelligence into your own environment
- Automating recurring checks instead of repeating them by hand
02Vulnerability management
The part where a long list becomes a justified order of work.
- Planning and running scans, and reading their results critically
- Recognising false positives before they cost effort
- Prioritising by exploitability and by actual business impact
- Tracking remediation and evidencing that it worked
03Incident response and management
What happens once an alert has become a confirmed incident.
- The phases of incident response from preparation through to review
- Containment, eradication and recovery in the right order
- Preserving evidence so that it survives an investigation
- Root cause analysis, so the same incident does not happen twice
04Reporting and communication
The smallest domain at 16 percent, and the one analytical work most often fails on.
- Preparing findings differently for engineering and for management
- Metrics that support a decision, rather than numbers that only impress
- Reporting obligations and coordination with others during an incident
- Wording recommendations so that they can actually be acted on
Outcome
What you will be able to do afterwards
- 01
You assess alerts by context and separate noise from real incidents.
- 02
You analyse log and network data and evidence an attack path with it.
- 03
You prioritise vulnerabilities by exploitability and business impact.
- 04
You plan vulnerability scans and interpret their results critically.
- 05
You carry out the incident response steps from containment through to recovery.
- 06
You preserve evidence so that it survives a later investigation.
- 07
You write findings up so that engineering and management can decide from them.
CompTIA Cybersecurity Analyst (CySA+)
CompTIA awards the certification once you pass the examination. It evidences analytical work: detection, assessment and response, rather than planning measures. Unlike the certificates of many other schemes this certification expires three years after you pass; you keep it valid with 60 continuing education units, or renew it by earning a higher CompTIA certification.
Certification terms comptia.org ↗Examination
CompTIA CySA+ examination
750Pass mark, scale to 900
- Questions
- max. 85
- Working time
- 165 min
- Format
- Multiple Choice + PBQ
- Delivery
- Pearson VUE / OnVUE
- Exam language
- EN
Pearson VUE administers the examination, not tecnovy, at a test centre or online proctored. At 165 minutes it is the longest on this board. Exam version as of August 2026: CS0-004; the previous CS0-003 retires in English on 22 December 2026.
Official examination rules comptia.org ↗Proof of attendance
Certificate of participation
≥80%attendance
The tecnovy certificate of participation records your attendance of the CompTIA CySA+ training, not a passed CompTIA examination.
Open the Certificate Showroom tecnovy → Offer scope
What the course price does not cover
Not included
- Fee for the CompTIA examinationThe examination fee is not included in the seminar price, comes to around CHF 350 excl. VAT (about EUR 375) and can be added at the booking step, which shows the amount converted at the daily rate.
Trainers
Why tecnovy
What you get on top with us
01
No Slideshow, Hands-On!
Promised: no PowerPoint marathon. We work in groups, tie theory to practice, and you get real project examples from our experienced trainers plus the exchange with like-minded people.
02
Certificate Showroom
Get your certificate of participation and, if you have one, add your exam certificate from E-Learning. Fully automated, beautifully designed. Just for you, only at tecnovy.
03
Flexible Date Change
If you are not able to attend the course, you can rebook your training free of charge up to one week before the start of the training.
04
Attend Twice, Pay Once
You are welcome to visit the training course online again within a year as a refresher or exam preparation.
05
Learn from Experts
We always guarantee you the use of didactically and methodically first-class qualified trainers who draw their knowledge from training experience as well as professional practical and project experience.
FAQs
Frequently asked questions
01Which exam version does the training cover?
02What language is the examination in?
03What is the difference between CySA+ and Security+?
04Do I need Security+ before CySA+?
05How long is the CompTIA CySA+ certification valid?
06What happens if I do not pass the examination?
07What materials do I receive?
What does your training at tecnovy look like?