Skip to content
Getting Digital
CompTIA certificationsCompTIA · exam CS0-004

CompTIA CySA+

CySA+ certifies the security analyst's work: monitoring, detecting, investigating and responding, plus the vulnerability management that occupies most of the calmer days.

Two and three quarter hours, longer than most papers covered here, and 750 needed.

Exam facts

Exam code
CS0-004
Level
Professional
Field
Cybersecurity
Duration
165 minutes
Questions
maximum of 85 (multiple choice and performance-based items)
Passing score
750 on a scale of 100 to 900
Languages
EnglishCompTIA announces French, Japanese, Spanish and Portuguese editions of CS0-004; the previous version CS0-003 stays bookable in English until 22 December 2026 and in Japanese, Portuguese and Spanish until 23 March 2027.
Price
439 USD (read 8 September 2026)
Validity
3 years, renewable
Exam delivery
Pearson VUE (test centre or online proctored)

Prerequisites: No formal prerequisites. CompTIA recommends Network+ and Security+ or equivalent knowledge and about four years as a SOC or vulnerability analyst.

Renewal: Continuing Education: 60 CEUs within three years, or pass the current CySA+ exam

Source: exam page at CompTIA · Price: CompTIA list price since the June 2026 price round (partner price list, read 2026-09-08); CompTIA shows your local price in its purchase widget

How to prepare

  1. Book the exam

    Delivered by Pearson VUE (test centre or online proctored). Schedule with CompTIA (opens in a new tab)

A version change in progress

  • CS0-004 is the current version, launched in June 2026.
  • CS0-003 retires in English on 22 December 2026 and in the other editions during March 2027.
  • English is the only language for CS0-004 at present, with further editions described by the vendor as coming.
  • Our practice-test partner lists only the retired version, so nothing current exists for us to point at, and naming that beats linking the superseded one.
  • A pass on either version is a pass; what you hold is the credential, not the paper code.

Written for people who already sit the seat

About four years of analyst work is the recommended background

That is not a gate and it is not decoration either. The questions assume you have triaged something at volume, closed a false positive badly, and argued about whether a vulnerability with a frightening score actually mattered in your environment. Candidates arriving straight from an entry certificate can pass with effort, and they describe it as the hardest paper in this vendor's range for a reason.

The length tells you the same thing. At 165 minutes for a maximum of 85 questions this is the longest CompTIA sitting covered here, and the extra time is not generosity: the performance-based items sit you at log data, alert queues and vulnerability output and expect you to reach a conclusion, which takes minutes rather than seconds. Multiple-choice stems are long as well, because each describes an incident with enough detail to make two answers plausible. The pass mark is 750 on the usual scale from 100 to 900.

DomainShareWhat it looks like on the day
Security operations34 %Reading telemetry, tuning detections, deciding what an alert means
Vulnerability management26 %Scanning output, prioritisation, and arguing a score down or up
Incident response and management24 %Containment, evidence, and the order things happen in
Reporting and communication16 %The part analysts skip and the exam does not

Against its neighbours

Below it sits Security+, which this paper assumes along with Network+, and passing this renews both automatically inside CompTIA's programme. Beside it sits PenTest+, its offensive twin at the same tier and the same fee; defence has far more seats than offence, which is worth weighing before choosing on interest. Across the aisle sits Microsoft's analyst exam, narrower and tied to one toolchain, which is the better purchase for somebody already inside a Microsoft-based operations team and the worse one for anyone who wants the certificate to travel.

Three years is the term, and 60 continuing-education credits keep it current, failing which you pass whatever version is current at the time. The credits are the realistic route for a working analyst, because the work itself generates most of them, and because a resit in three years would be against a version that does not exist yet. Prepare for the current paper on the exam objectives and on real data rather than on more reading; the objectives are published, the data is in your own environment, and the mock sitting we would normally recommend does not exist for this version.

What a question looks like

Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.

A scanner reports a critical vulnerability on an internal server. The affected service is not running, the port is closed at the host firewall, and the package is installed but unused. The business asks whether this needs emergency patching. What is the correct assessment and why?

The score says critical and the situation says otherwise, which is the daily reality of vulnerability management and almost never how the subject is taught. The exam wants you to reason about exploitability in context rather than deferring to a number, and to justify the answer to somebody non-technical. Candidates who treat the scanner as authoritative get this wrong consistently.

What it costs to get and to keep

ItemAmountNote
Exam fee439 USDpartner price list after CompTIA's June 2026 price round; the vendor shows prices only in its own purchase widget, by country (read 8 September 2026)
Practice testnot publishedour partner lists only the retired CS0-003 product, so there is no current practice test we can recommend for this version (read 12 September 2026)
Renewal every three yearsnot published60 continuing-education credits, or passing the current CySA+ exam again. This also renews Security+ and everything below it (read 12 September 2026)

How much preparation, from where you are

You work in a security operations centre
The exam is your job formalised. Expect the vulnerability management and reporting domains to need the most attention, because analysts often inherit those processes rather than design them.
You hold Security+ and want to specialise
A real step rather than the next rung. The gap is operational experience, and a home lab with real log data closes more of it than any course.
You administer systems and respond to incidents occasionally
Better positioned than you think. You have seen the events; what you lack is the analyst's framework for deciding which ones matter and how to write that decision down.

What passing this does not prove

  • Any particular tooling, which is deliberate and makes it feel abstract next to a vendor exam.
  • Whether you can stay accurate at hour six of an incident.
  • The organisational work of getting a patch approved, which is where most vulnerabilities actually live.
  • Threat hunting at any depth beyond the vocabulary.

Against the alternatives

SC-200Microsoft Certified: Security Operations Analyst Associate
Microsoft's analyst exam is narrower and concrete, tied to a specific toolchain you may already use. Sit it to evidence the platform; sit this to evidence the craft.
SY0-701CompTIA Security+
The entry paper below, and the prerequisite in spirit. Passing this renews it automatically.
PT0-003CompTIA PenTest+
The offensive counterpart at the same tier. Defence has far more seats than offence, which is worth weighing before choosing on interest alone.

CS0-004 — quick answers

Which version should I sit?

The current one, CS0-004, unless you are already deep into preparation for CS0-003 and can sit it before it retires in English on 22 December 2026. A pass on either yields the same certificate.

Is it available in my language?

Not yet, unless that language is English. CompTIA describes further editions as coming without committing to dates, and the previous version's other editions run until March 2027, which is worth checking against your own timeline.

Do I need four years of experience?

It is a recommendation, not a requirement, and it is unusually accurate. The questions assume patterns you learn by doing the work. Without that background, budget considerably more time and get access to real log data, because the scenarios are written for people who recognise them.

How should I prepare without a practice test?

Use the exam objectives as a checklist against your own environment, and spend the time in a lab rather than on more reading. Ordinarily we would name a mock sitting written to the exam's format, and none exists for this version, so we are not going to invent a recommendation.

Why is the reporting domain examined at all?

Because an analyst who cannot explain a finding to somebody who will act on it has not finished the job, and the exam is built by people who have read enough bad incident reports to know it. Sixteen percent of the paper is a smaller share than the technical domains and a larger one than most candidates prepare for.

What comes next

Concepts this exam draws on

Glossary entries with the reason each one matters for CS0-004.

  • SSL/TLS

    Analysts read certificate and TLS anomalies in logs and captures.

  • SIEM

    Security operations is the largest domain and correlating events in a SIEM is its daily work.

  • IDS/IPS

    Reading and tuning detection output is examined as the analyst's core skill.

  • Vulnerability Management

    A quarter of the paper: scan output, prioritisation and arguing a score up or down.

  • Incident Response

    The response domain covers containment, evidence and the order things happen in.

  • SOC

    The exam is written for the person who sits in one.

  • Phishing

    Email-borne attacks are the commonest incident an analyst triages, and the exam knows it.

A vendor certificate — not a degree and not an accredited qualification. Facts are from the vendor's exam page on the date shown; prices are list prices that vary by country and tax.

Last reviewed 12 September 2026 · Getting Digital