CySA+ is CompTIA's intermediate analyst certification. It checks whether you can work as a security analyst: watch systems, spot malicious activity, run a vulnerability program, respond to incidents and explain what happened to the people who need to act on it.
CS0-004 went live on June 23, 2026 and replaced CS0-003 the same day. If you studied from CS0-003 material, most of the analyst fundamentals still apply, but V4 adds more cloud and hybrid environments, more automation (SOAR and scripting) and new coverage of AI in security operations. This course is written to the V4 domain structure.
The four domains
- 1.0 Security Operations – 34%
- 2.0 Vulnerability Management – 26%
- 3.0 Incident Response and Management – 24%
- 4.0 Reporting and Communication – 16%
The weights are flat compared with most CompTIA exams. Even the smallest domain is roughly one question in six, so no area is safe to skip. Plan your study time in proportion: about a third on security operations, a quarter each on vulnerabilities and incident response, and the rest on reporting.
Question types
You will see standard multiple-choice items and performance-based questions (PBQs). PBQs put you in front of something realistic – a log excerpt, scan output, a firewall rule list or an incident timeline – and ask you to interpret it, classify it or put steps in order. They usually appear at the start of the exam.