CompTIA CySA+ (CS0-003) Exam Preparation
A two-day intensive on the CS0-003 blueprint for people who actually work an alert queue. Where Security+ establishes that you understand controls, CySA+ tests whether you can use them: read telemetry, tell a true positive from noise, prioritise a vulnerability backlog that will never reach zero, and write the incident report that a manager and a regulator will both read.
The programme follows the four exam domains and stays deliberately hands-on, working from log extracts, scan output and packet summaries rather than definitions. It suits analysts in a SOC or a small internal security team, and IT staff who have inherited detection and response duties without a formal analyst role. This is exam preparation rather than accredited delivery: the exam is booked with Pearson VUE and the voucher is arranged separately. Security+ level knowledge or equivalent working experience is assumed throughout.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Exam Orientation
Exam format including the performance-based questions, domain weighting, and how CySA+ questions differ from Security+ in what they ask you to do.
Day 1, 9:15 AM - 11:00 AM
Domain 1: Security Operations, Part 1
The largest domain. System and network architecture concepts as they affect detection: logging, operating system fundamentals, network architecture, identity and access management, encryption and sensitive data protection. Standard versus deviation as the basis of all detection. Analysing indicators of malicious activity across network, host and application: unusual traffic, beaconing, rogue devices, scans, processes, memory, unauthorised changes, service interruption and social engineering indicators.
Day 1, 11:00 AM - 11:15 AM
Break
Day 1, 11:15 AM - 12:45 PM
Domain 1: Security Operations, Part 2
Tools and techniques in practice: packet capture, log analysis and correlation, endpoint and DNS telemetry, email analysis including headers, file analysis, sandboxing and hashing. Threat intelligence: confidence levels, collection methods, indicator management, threat actor classification and TTPs. Applying the frameworks the exam expects you to reason with, including MITRE ATT&CK, the Diamond Model, the Cyber Kill Chain and OSINT. Threat hunting: hypothesis, focused search, bundling and reducing the attack surface.
Day 1, 12:45 PM - 1:45 PM
Lunch
Day 1, 1:45 PM - 3:15 PM
Domain 1: Efficiency and Process Improvement
Standardising processes and streamlining operations, which the exam treats as an analyst skill rather than a manager's. Automation and orchestration, scripting, API integration, single pane of glass, and where automation reliably fails. Technology and tool integration. Working through a live alert triage exercise from raw telemetry to a documented finding.
Day 1, 3:15 PM - 3:30 PM
Break
Day 1, 3:30 PM - 4:45 PM
Domain 2: Vulnerability Management, Part 1
Discovery and scanning: asset discovery, active and passive scanning, credentialed versus non-credentialed, agent versus agentless, internal and external, and scanning special-purpose systems. Industry frameworks and standards including CVE, CVSS, CWE, OWASP, SCAP and the exposure feeds. Static and dynamic analysis, software composition analysis and the security implications of the software supply chain.
Day 1, 4:45 PM - 5:00 PM
Day 1 Close and Evening Study Set
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Working the evening set and clearing the questions that caused trouble.
Day 2, 9:15 AM - 10:45 AM
Domain 2: Analysis, Prioritisation and Response
Validating findings: true positive, false positive, true negative and false negative, and what each one costs you. Context awareness in prioritisation. CVSS scoring in depth including base, temporal and environmental metrics, and why the raw score is the beginning of the argument rather than the end. Weaponisation, exploit availability and asset value. Controls: patching, configuration management, compensating controls, segmentation and exceptions. Risk acceptance and the formal exception process. Attack techniques the exam expects you to recognise, including injection, privilege escalation, request forgery and directory traversal.
Day 2, 10:45 AM - 11:00 AM
Break
Day 2, 11:00 AM - 12:45 PM
Domain 3: Incident Response and Management
Attack methodology frameworks applied to a live case. The full incident response lifecycle: preparation, detection and analysis, containment, eradication and recovery, and post-incident activity. Evidence acquisition and chain of custody. Scoping and impact analysis, including how far to look before declaring containment. Root cause analysis. Lessons learned that change a control rather than a document. Working a full simulated incident from first alert through to containment decision.
Day 2, 12:45 PM - 1:45 PM
Lunch
Day 2, 1:45 PM - 3:15 PM
Domain 4: Reporting and Communication
Vulnerability management reporting: compliance reports, action plans, inhibitors to remediation such as MOUs, SLAs, business process interruption and legacy systems. Metrics and KPIs including SLOs and risk score. Incident reporting: stakeholder identification, incident declaration, escalation and communication to legal, HR, regulators, customers and the media. Root cause and lessons learned reports. Mapping notification duties onto Malaysian obligations under the PDPA and, for NCII entities, the Cyber Security Act 2024.
Day 2, 3:15 PM - 3:30 PM
Break
Day 2, 3:30 PM - 4:30 PM
Full-Length Practice Assessment
A timed practice set under exam conditions including performance-based items, scored and reviewed by domain.
Day 2, 4:30 PM - 5:00 PM
Exam Strategy, Study Plan and Close
Managing the clock on a question set that runs long, handling the performance-based items, and a personalised study plan before the attempt.
Key Outcomes
- Analyse network, host and application telemetry to separate genuine incidents from noise
- Apply MITRE ATT&CK, the Diamond Model and the Cyber Kill Chain to real analysis rather than as recall
- Run and interpret vulnerability scans, and prioritise a backlog using CVSS in context
- Work an incident through the full lifecycle, preserving evidence and scoping impact correctly
- Write vulnerability and incident reports that hold up with management, legal and regulators
- Sit the CS0-003 exam with a scored diagnostic and a personalised study plan behind you
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate to advanced. Suitable for security analysts, SOC staff, threat hunters and IT professionals with detection and response duties. CompTIA suggests around four years of hands-on experience. Security+ level knowledge is assumed.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A timed full-length practice assessment scored by domain, plus a full simulated incident worked end to end. The CompTIA exam itself is booked with Pearson VUE and the voucher is arranged separately.
Certificate Orbix Certificate of Completion issued to all participants upon full attendance. This is a training certificate, not the CompTIA credential. CySA+ is awarded by CompTIA only on passing the CS0-003 exam, which is booked and paid for separately.