
CompTIA CySA+ (CS0-003)
Exam CS0-003 CompTIA Intermediate
The blue-team analyst certification and the natural step after Security+. Detection, threat hunting, incident response and vulnerability management.
Free resources
The path
Step 1 — Learn the analyst body of knowledge
Threat intelligence, monitoring, response and reporting.
2 courses
Learn
- CourseCompTIA CySA+ Cybersecurity Analyst (CS0-003): The Total Course 🔒 StationX Unlimited
20 sections · 107 lectures
- Training Overview 2
- Chapter 00: Introduction 3
- Chapter 01: Security Operations: System Fundamentals 9
- Chapter 02: Security Operations: Infrastructure Types 4
- Chapter 03: Attack Methodology Frameworks 2
- Chapter 04: Security Operations: Network Architecture, Access & Data 6
- Chapter 05: Security Operations: AI & Automation 10
- Chapter 06: Indicators of Attack (IoA) 6
- Chapter 07: Threat Intelligence 4
- Chapter 08: Security Operations Tools: Detection & Investigation 6
- Chapter 09: Security Operations Tools: Vulnerability Assessment 7
- Chapter 10: Vulnerability Scanning Methods 15
- Chapter 11:Vulnerability Assessment & Prioritization 4
- Chapter 12:Application Security & Attack Mitigation 5
- Chapter 13:Vulnerability Response: Controls & Risk Management 14
- Chapter 14: Vulnerability Response: Remediation & Reporting 3
- Chapter 15: Evidence & Data Protection 3
- Chapter 16: Incident Response 2
- Next Steps & Certification 1
- Audio Version of Training 1
- CourseCompTIA CySA+ (CS0-003) Complete Course 🔒 StationX Unlimited
42 sections · 361 lectures
- Training Overview 1
- Introduction to CompTIA CySA+ 4
- Foundational Security Operations 6
- Risk Management and Security Controls 7
- System Infrastructure Concepts 8
- Threat Hunting and Modeling 11
- Network-Related IoC 9
- Appliance Monitoring 11
- Endpoint and Domain Analysis 10
- Social Engineering and Email Attacks 9
- Configuring Your SIEM 8
- SIEM and Log Analysis 9
- Digital Forensics 14
- Indicators of Compromise (IoC) 14
- Host-Related IoC 11
- Application and Cloud-Related IoC 9
- Analyzing Lateral Movement and Pivoting IOCs 7
- Incident Response Preparation 10
- Detection and Containment 7
- Incident Containment, Eradication, and Recovery 10
- Risk Mitigation 9
- Frameworks, Policies, and Procedures 8
- Enumeration Tools 16
- Vulnerability Scanning 12
- Analyzing Output from Vulnerability Scanners 10
- Mitigating Vulnerabilities 6
- Identity and Access Management 12
- Network Architecture Concepts 11
- Hardware Assurance Best Practices 6
- Specialized Technology 9
- Non-technical Data and Privacy Controls 9
- Technical Data and Privacy Controls 10
- Mitigate Software Vulnerabilities and Attacks 10
- Mitigate Web Application Vulnerabilities and Attacks 13
- Analyzing Application Assessments 9
- Cloud and Automation 6
- Service-Oriented Architecture 10
- Cloud Infrastructure Assessment 6
- Automation Concepts and Technologies 10
- Practice Test: CompTIA CySA+ (CS0-003) Practice Test 1
- Conclusion 2
- Audio Version of Training 1
Step 2 — Threat intelligence and detection
Turn intelligence into detections that fire on real activity.
37 labs
Learn
- CourseCovered in CompTIA CySA+ Cybersecurity Analyst (CS0-003): The Total Course — threat intelligence and detection sections 🔒 StationX Unlimited
Practise
- Labs+Security Threat Intelligence — 11 labs 🔒 StationX Labs+
- Assess Cybersecurity Templates and Benchmarks [Guided]
- Can You Discover Vulnerabilities Over a Network? [Advanced]
- Can You Establish Secure Communications by Using SSH and Wireshark? [Advanced]
- Can You Manage Threats by Using Source Code, Logs, and Security Templates? [Advanced]
- Can You Reduce Threats by Using Nmap, SSH, Source Code Analysis, and Security Templates? [Expert]
- Find Vulnerabilities [Guided]
- Perform Application Source Code Verification [Guided]
- Perform Log Analysis [Guided]
- Perform Network Scanning [Guided]
- Use SSH for Remote Access [Guided]
- Use Wireshark Filters to Explore Captured Network Traffic [Guided]
- LabsThreat Intelligence & Defense — 18 labs 🔒 StationX Unlimited
- Analyze Various Data Sources to Confirm Suspected Infection
- Assessing Vulnerabilities Post Addressal
- BitCoin Mining Web Application on Corporate Network
- Check for Indicators of Other Attack Activity (Debug PE File)
- Cyber Security Evaluation Tool (CSET)
- Entering Information into a CMDB
- Event Logs with Autopsy
- Internet History
- MITRE - Defend
- Nexpose: Red Team Exploitation
- Overview of Kibana
- Performing an Initial Attack Analysis
- Preparing Target Media
- Recover from Illegal Bitcoin Mining Incident
- Recover from Web-Based Flashpack Incident
- Report Writing for Presentation to Management
- Respond to and Validate Alerts from Antivirus Software
- WMI Event Persistence
- LabsNetwork Intrusion Detection — 8 labs 🔒 StationX Unlimited
Free resources
Step 3 — Vulnerability management
Scan, interpret, prioritise and drive remediation.
61 labs
Learn
- CourseCovered in CompTIA CySA+ Cybersecurity Analyst (CS0-003): The Total Course — vulnerability management sections 🔒 StationX Unlimited
Practise
- LabsVulnerability Assessment Analyst — 31 labs 🔒 StationX Unlimited
- Analyze SQL Injection Attack
- Analyze and Update a Company BCP/BIA/DRP/CIRP
- Auditing Service Accounts and Setting Up Automated Log Collection
- Centralized Monitoring
- Comprehensive Threat Response
- Conduct Log Analysis and Cross Examination for False Positives
- Core Impact Web Application Penetration Testing
- Creating Recommendations Based on Vulnerability Assessments
- Data Backup to Prep for Recovery
- Firewall Setup and Configuration
- Gap Analysis of Firewall Rules
- Identify Whether High-Risk Systems Were Affected
- Identifying System Vulnerabilities with OpenVAS
- Implementing Least-Privilege on Windows
- Manual Vulnerability Assessment
- Manually Creating a Baseline with MD5Deep
- Monitoring and Verifying Management Systems
- Network Discovery
- Network Segmentation (FW/DMZ/WAN/LAN)
- Open Source Password Cracking
- Penetration Tester Challenge
- Performing an Initial Attack Analysis
- Phishing
- Preliminary Scanning
- SNORT Configuration and Operation Lab
- Threat Designation
- Using Snort and Wireshark to Analyze Traffic
- Vulnerability Proof of Concept and Remediation
- Vulnerability Scanning with GVM
- Windows System Hardening with Group Policy & Active Directory
- Windows System Hardening with PowerShell
- Labs+Introduction to Vulnerability Analyst — 10 labs 🔒 StationX Labs+
- Can You Implement Intrusion Detection by Using Wazuh? [Advanced]
- Can You Improve Network Security with SSH, HTTPS, and IPSec? [Advanced]
- Can You Improve Security by Using Network Scanning, Sniffing, and GPOs? [Advanced]
- Can You Use Snort and SSH? [Expert]
- Configure Secure HTTP Services [Guided]
- Configure and Manage SSH to Establish Secure Connections [Guided]
- Configuring VPN Services [Guided]
- Implement Intrusion Detection by Using Wazuh [Guided]
- Manage Incidents by Using Incident Response Tools [Guided]
- Perform Network Scanning and Reconnaissance [Guided]
- Labs+CySA+: Identify Network Vulnerabilities — 11 labs 🔒 StationX Labs+
- Can You Implement a Host-Based Intrusion Detection System? [Advanced]
- Can You Manage Network, Web, and Remote Access Security? [Advanced]
- Can You Perform Network and Vulnerability Scanning? [Advanced]
- Can You Use Snort, IPSec, Wireshark, Nikto, Nmap, and Wapiti to Identify Network Vulnerabilities? [Expert]
- Establish Secure Communications Between Systems by Using SSH for Remote Access [Guided]
- Harden Network Security [Guided]
- Implement Snort to Evaluate Network Communications [Guided]
- Implement a Host-Based Intrusion Detection System [Guided]
- Perform Network Scanning to Find Vulnerabilities [Guided]
- Perform Web Server Vulnerability Scans [Guided]
- Use Reconnaissance Tools to Perform Network Scanning [Guided]
- Labs+CySA+: Vulnerability Assessment Tools — 9 labs 🔒 StationX Labs+
- Use Greenbone Security Manager to Identify Vulnerabilities [Guided]
- Use Nmap for Enumeration [Guided]
- Use Responder for Enumeration [Guided]
- Use Web Application Scanners [Advanced]
- Use hping for Enumeration [Guided]
- Use the Arachni Web Application Scanner [Guided]
- Use the Nikto Web Application Scanner [Guided]
- Using the Burp Suite Web Application Scanner [Guided]
- Using the OWASP Zed Attack Proxy Web Application Scanner [Guided]
Free resources
Step 4 — Incident response
Work an incident end to end, then restore and report.
1 course · 101 labs
Learn
- CourseCompTIA CySA+ Labs 🔒 StationX Unlimited
9 sections · 93 lectures
- New section 0
- Module 1 - Threat and Vulnerability Management 28
- Module 2 - Incident Response 10
- Module 3 - Software and Systems Security 11
- Module 4 - OSINT (Open-Source Inteligence) 8
- Module 5 - Digital Forensics 20
- Module 6 - Malware Analysis 11
- Module 7 - Red Team Adversary Emulation 2
- Module 8 - Bonus Labs 3
Practise
- LabsCyber Defense Incident Responder — 34 labs 🔒 StationX Unlimited
- Analyze SQL Injection Attack
- Analyze and Update a Company BCP/BIA/DRP/CIRP
- Applying Filters to TCPDump and Wireshark
- Block Incoming Traffic on Known Port
- Comprehensive Threat Response
- Cryptography: Steganography
- Cryptography: Using GPG for Encryption and Key Management
- Data Backup to Prep for Recovery
- Data Recovery with Autopsy
- Dynamic Malware Analysis
- Firewall Setup and Configuration
- Hash Verification
- Identify Whether High-Risk Systems Were Affected
- Implement Single System Changes in Firewall
- Installing Patches and Testing Software
- Introduction to Squert
- Log Event Reports
- Microsoft Baseline Security Analyzer
- Monitoring Network Traffic
- Network Discovery
- Network Segmentation (FW/DMZ/WAN/LAN)
- Network Topology Generation
- Overview of Kibana
- Recover from Incident
- Report Writing for Presentation to Management
- Setting Up Zones in a Firewall
- Setting up Filters and Queries in Kibana
- Threat Designation
- Validate Indications of Compromise: Analysis of PE File
- Vulnerability Analysis/Protection
- WebApp Attack PCAP Analysis
- Windows Event Log Manipulation via Windows Event Viewer
- Windows System Hardening with Group Policy & Active Directory
- Windows System Hardening with PowerShell
- Labs+Cyber Security Incident Response — 11 labs 🔒 StationX Labs+
- Can You Examine Network Communications by Using Incident Response Tools? [Advanced]
- Can You Manage Logs with Scripts, Perform File Restoration, and Perform Vulnerability Scans? [Advanced]
- Can You Perform File Restoration, Manage GPOs, and Perform OSINT? [Expert]
- Can You Use GPOs and Security Templates as Part of IR? [Advanced]
- Evaluate and Customize Security Policy Templates [Guided]
- Explore Network Traffic by Using Wireshark [Guided]
- Find Network System Vulnerabilities [Guided]
- Implement New Security Policies [Guided]
- Perform Backup Options to Allow for Lost File Restoration [Guided]
- Perform Log Analysis and Task Automation [Guided]
- Perform Open Source Intelligence (OSINT) Gathering Operations [Guided]
- LabsCyber Defense Analyst Training Series — 56 labs 🔒 StationX Unlimited
- Additional Scanning Options
- Advanced Techniques for Malware Recovery
- Analysis and Recommendation Report
- Analyze SQL Injection Attack
- Analyze Various Data Sources to Confirm Suspected Infection
- Analyze and Classify Malware
- Applying Filters to TCPDump and Wireshark
- Assessing Vulnerabilities Post Addressal
- Block Incoming Traffic on Known Port
- CIRP Creation and Disaster
- Centralized Monitoring
- Collecting Logs and Verifying Syslog Aggregation
- Comprehensive Threat Response
- Conduct Root Cause Analysis for System Crashes
- Core Impact Web Application Penetration Testing
- Create Custom Snort Rules
- Creating Recommendations Based on Vulnerability Assessments
- Creating SIEM Reports with Splunk
- Disable User Account on Windows 10
- Firewall Setup and Configuration
- Gap Analysis of Firewall Rules
- IDS Setup and Configuration
- Identify Whether High-Risk Systems Were Affected
- Identifying Malicious Network Connections
- Identifying System Vulnerabilities with OpenVAS
- Implement Single System Changes in Firewall
- Linux Users and Groups
- Log Analysis
- Log Correlation
- Manual Vulnerability Assessment
- Manually Creating a Baseline with MD5Deep
- Microsoft Baseline Security Analyzer
- Monitoring Network Traffic
- Monitoring and Verifying Management Systems
- Monitoring for False Positives
- Network Discovery
- Network Segmentation (FW/DMZ/WAN/LAN)
- Network Topology Generation
- Open and Close Ports on Windows 7
- Parse Files Out of Network Traffic
- Preliminary Scanning
- Protect Against Beaconing
- Recover from Incident
- Recover from SQL Injection Attack
- Report Writing for Presentation to Management
- Searching for Indicators of Compromise
- Setting Up SYSLOG Forwarding From a Windows System
- Threat Designation
- Using Snort and Wireshark to Analyze Traffic
- Vulnerability Analysis/Protection
- Vulnerability Scanner Set-up and Configuration
- Vulnerability Scanner Set-up and Configuration with OpenVAS
- Vulnerability Scanning with GVM
- Whitelist Comparison
- Windows System Hardening with Group Policy & Active Directory
- Windows System Hardening with PowerShell
Free resources
Step 5 — Log analysis and SIEM
Correlate across sources and find the signal.
31 labs
Learn
- CourseCovered in CompTIA CySA+ Cybersecurity Analyst (CS0-003): The Total Course — log analysis and SIEM sections 🔒 StationX Unlimited
Practise
- LabsQRadar SIEM — 9 labs 🔒 StationX Unlimited
- Event Log Collection with QRadar
- QRADAR - Auditing Service Accounts and Generating SIEM Reports
- QRADAR - Collecting Logs and Verifying Syslog Aggregation with pfSense
- QRADAR - Setting Up SYSLOG Forwarding From a Windows System
- QRadar - Centralized Monitoring
- QRadar - IDS Setup and Configuration
- QRadar - Log Correlation & Analysis to Identify Potential IOC
- QRadar - Log Correlation & Analysis to Identify Potential IOC with Custom Log Types
- QRadar - Snort Signatures, IDS Tuning, and Blocking
- LabsCritical Security Controls — 22 labs 🔒 StationX Unlimited
- Auditing Service Accounts and Setting Up Automated Log Collection
- BitLocker Setup
- CIRP Creation and Disaster
- Centralized Monitoring
- Comparing Controls
- Creation of Standard Operating Procedures for Recovery
- Data Backup to Prep for Recovery
- Data Downloads and Validation
- Force Point: DLP Email Overview
- Force Point: DLP Network Overview
- Identifying Key Assets
- Leveraging Internal Intelligence Resources
- Log Correlation & Analysis to Identify Potential IOC
- Monitoring and Verifying Management Systems
- Open and Close Ports on Windows 7
- Phishing (2026)
- Phishing
- Post Incident Service Restoration
- Ransomware
- Recover from SQL Injection Attack
- Sensitive Information Identification
- Vulnerability Identification and Remediation
Free resources
Before the exam
- FreeFree CySA+ Performance Based Questions (PBQs)
- FreeCompTIA Certification Costs: What to Budget
- CourseCompTIA CySA+ CS0-003: The Ultimate Practice Exam 🔒 StationX Unlimited
3 sections · 9 lectures
- Practice Tests 4
- Practice Question by Question 4
- Next Steps & Certification 1
- CourseCompTIA CySA+ Practice Questions and Flashcards 🔒 StationX Unlimited
3 sections · 6 lectures
- Practice Questions 1
- Practice Flashcards 4
- Next Steps & Certification 1
Where this leads
- Advanced Security Practice (SecurityX / CASP+ aligned) — Advanced
- CISSP — Certified Information Systems Security Professional — Advanced
- Threat Hunter — career path — Advanced
- Incident Responder — career path — Intermediate
- Threat Intelligence Analyst — career path — Advanced
- FreeCySA+ Salary: How Much Can You Make?
- FreeAre SOC Analysts in Demand?