CompTIA CySA+: Detecting, Preventing and Responding to Incidents
Security alerts should lead to relevant analysis and action. Structure detection, triage and investigation to distinguish useful signals from noise. Strengthen your ability to document incidents and coordinate their handling within the defensive framework.
- Duration
- 5 days 35 hours
- Code
- C-CYSA Code
- Certification
- CompTIA Cybersecurity Analyst (CySA+) Certification
Accredited training for the CompTIA Cybersecurity Analyst (CySA+) certification.
Presentation
CompTIA CySA+ is an IT security certification focused on analysis and incident response. Recognised worldwide, it strengthens your credibility and value in the job market. As a CompTIA CySA+-certified professional, you will be better prepared to identify and mitigate security threats. Growing demand for cybersecurity experts also makes this certification a pathway to broader and often better-paid career opportunities.
Our 5-day CompTIA CySA+ course provides the skills and knowledge to detect, prevent and respond to cybersecurity incidents. You will explore security operations activities, vulnerability management, incident response and management, reporting and communication in detail.
The program's 4 skill domains prepare you for the CompTIA CS0-003 exam, included in our offer. This exam is a prerequisite for CompTIA CySA+ certification (see the Certification tab for details).
Objectives
By the end of this course, you will be able to:
- detect and analyse indicators of compromise (IOCs);
- understand threat detection and threat intelligence principles;
- use appropriate tools and methods to manage, prioritise and respond to attacks and vulnerabilities;
- execute an incident response procedure;
- understand reporting and communication for vulnerability management and incident response activities;
- take the CS0-003 exam and earn CompTIA CySA+ certification.
Program
1. Security operations
- Understand system and network architecture concepts in security operations.
- Analyse indicators of potentially malicious activity in a scenario involving networks, hosts, applications, social engineering attacks and concealed URLs.
- Use appropriate tools or techniques to identify malicious activity in a defined scenario.
- Compare and contrast threat intelligence and threat hunting concepts.
- Understand the importance of process improvement in security operations.
2. Vulnerability management
- Apply vulnerability assessment methods and concepts to a scenario.
- Analyse vulnerability assessment tool results in a scenario.
- Analyse data to prioritise vulnerabilities in a scenario.
- Recommend control procedures to mitigate software attacks and vulnerabilities in a scenario.
- Understand vulnerability response, tracking and management concepts.
3. Incident response and management
- Understand cybersecurity framework concepts:
- the kill chain principle;
- the Diamond Model of Intrusion Analysis;
- the MITRE ATT&CK® framework;
- the Open Source Security Testing Methodology Manual (OSSTMM);
- the Open Web Application Security Project (OWASP) Testing Guide.
- Execute incident response activities in a scenario:
- detection and analysis;
- containment, eradication and recovery.
- Understand preparation and post-incident activity phases of the incident management life cycle.
4. Reporting and communication
- Understand the importance of reports and communication processes:
- vulnerability management reports;
- compliance reports;
- action plans;
- remediation barriers;
- metrics and key performance indicators (KPIs);
- identifying stakeholders and their communication methods;
- incident reporting and escalation;
- incident response reports;
- communication methods;
- root cause analysis;
- lessons learned.
Audience
This course is designed for:
- IT security, vulnerability and threat intelligence analysts seeking to master the configuration and effective use of threat detection tools;
- cybersecurity professionals seeking CompTIA CySA+ certification.
Prerequisites
The CompTIA CySA+ course requires:
- ability to read and understand English, Japanese, Portuguese or Spanish for the CompTIA CS0-003 exam.
- CompTIA Network+, CompTIA Security+ or equivalent certifications, and at least 4 years of hands-on experience as an incident response analyst or security operations centre (SOC) analyst, or equivalent experience (recommended).
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
Lessons to develop or validate cybersecurity risk analysis skills; training covering current technologies; the CompTIA CySA+ certification exam included in the offer.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
CompTIA® is a registered trademark of CompTIA Inc.
Certification guide
CompTIA
fr
en
