Start by confirming your exam code and language. Then use the matching objectives to plan study across all four CySA+ domains, practise interpreting evidence and work through the original prioritization exercise below.
Which version applies: CS0-004 versus retiring CS0-003
CS0-004 (V4) is the current version. CS0-003 (V3) remains available during its retirement period, so check your preparation, exam language and booking date before deciding.
V4 launched June 23, 2026. English is available; CompTIA lists French, Japanese, Spanish and Portuguese as coming soon. V3 English retires December 22, 2026, and its Japanese, Portuguese and Spanish exams retire March 23, 2027. English V3 learning products retire November 22, 2026, a different deadline from the exam.
If you already study V3, compare your planned date and remaining gaps with the applicable retirement deadline. You can retain accurate material that maps to your booked objectives. Do not assume an older resource covers every V4 topic or use V3 weights for V4.
V4 weights are 34%, 26%, 24% and 16%; V3 uses 33%, 30%, 20% and 17% for the corresponding domains. Confirm voucher compatibility with CompTIA before changing versions.
Facts come from CompTIA's official V4 and V3 certification pages, CompTIA's PBQ guidance and retake policy, and the CS0-004 V4 objectives document (a training-site-hosted copy).: CySA+ Certification V4 (New Version) | CompTIA — Exam details and V4 objectives summary; CySA+ Certification V3 (Retiring Version) | CompTIA — Retirement dates, V3 exam details and objectives summary; Cybersecurity Analyst+ (CySA+) Certification | CompTIA — Catalog page confirming V4 current and V3 retirement dates; CompTIA CySA+ CS0-004 V4 Exam Objectives (Document Version 2.0, training-site-hosted copy) — Test details, domain weights, objectives 1.1–4.2, accreditation and materials policy
What the CS0-004 exam measures
CS0-004 tests whether you can run incident response and vulnerability management processes, detect and analyze indicators of malicious activity, apply the right tools and frameworks, and communicate findings clearly.
The final V4 objectives are document version 2.0. The copy linked here is CompTIA-authored and hosted by a training site; CompTIA's current certification page corroborates the exam specifications.
The listed examples are not exhaustive. Use the complete objectives and supporting resources to cover each group; they are not an inventory of actual exam questions.
| Domain | Weight | Objective groups cover |
|---|---|---|
| 1.0 Security Operations | 34% | Architecture, logging and identity concepts; malicious activity indicators; analysis tools; threat intelligence and hunting; process improvement; AI in security operations |
| 2.0 Vulnerability Management | 26% | Scanning methods; assessment tool output; prioritization and mitigation; control types, risk and application security concepts |
| 3.0 Incident Response and Management | 24% | Attack methodology frameworks; the incident response process; response techniques including evidence, triage and remediation |
| 4.0 Reporting and Communication | 16% | Vulnerability reporting; incident and security operations communication, including handover and metrics |
Facts come from CompTIA's official V4 and V3 certification pages, CompTIA's PBQ guidance and retake policy, and the CS0-004 V4 objectives document (a training-site-hosted copy).: CompTIA CySA+ CS0-004 V4 Exam Objectives (Document Version 2.0, training-site-hosted copy) — Test details, domain weights, objectives 1.1–4.2, accreditation and materials policy; CySA+ Certification V4 (New Version) | CompTIA — Exam details and V4 objectives summary
Format, scoring and retake rules
V4 uses multiple-choice and performance-based items. The maximum is 85 questions, with 165 minutes and a scaled passing standard of 750 on 100-900.
CompTIA recommends roughly four years of hands-on experience in a SOC analyst or vulnerability analyst role. This describes intended preparation rather than a mandatory four-year admission requirement.
Do not convert the scaled score into a percentage or required number correct. The maximum question count does not promise that every exam has exactly 85 items.
After your first failed attempt, no wait is required before a second. Before a third or later attempt, wait at least 14 calendar days from your last attempt. The policy requires payment for each attempt; check any retake terms attached to your voucher or bundle.
Facts come from CompTIA's official V4 and V3 certification pages, CompTIA's PBQ guidance and retake policy, and the CS0-004 V4 objectives document (a training-site-hosted copy).: CySA+ Certification V4 (New Version) | CompTIA — Exam details and V4 objectives summary; CompTIA CySA+ CS0-004 V4 Exam Objectives (Document Version 2.0, training-site-hosted copy) — Test details, domain weights, objectives 1.1–4.2, accreditation and materials policy; CompTIA Certification Retake Policy | CompTIA IT Certifications — Waiting periods and per-attempt payment
How performance-based questions work
CySA+ includes simulation performance-based questions (PBQs): approximations of a tool or environment, such as a terminal window or network diagram, where you solve a realistic task rather than pick an option.
CompTIA's PBQ page places CySA+ in the simulation category. Simulations have restricted functionality, so do not assume every command you know is available, and there can be several valid routes to a correct result. Partial credit is possible, though which items offer it is confidential.
Simulation PBQs are flexible: you can skip one and return later, your work is saved as you move, and the Reset button clears only that question. That differs from the virtual-machine PBQ format used on some other CompTIA exams, where you must complete the item when you reach it.
A practical habit for practice sessions: read the task statement and constraints first, act deliberately, and note what you did. On exam day, if a simulation stumps you, moving on and returning is a sound use of the format's skip-and-return design.
Facts come from CompTIA's official V4 and V3 certification pages, CompTIA's PBQ guidance and retake policy, and the CS0-004 V4 objectives document (a training-site-hosted copy).: Performance-Based Questions Overview | CompTIA IT Certifications — Simulation vs virtual PBQs, skip/return behavior; Performance-Based Questions FAQs | CompTIA Blog — Reset behavior, multiple valid paths, partial credit
Building a study plan from the four domains
Use the objectives and your own gaps to decide what to practise. Combine evidence interpretation with explaining a decision clearly.
The following tasks are preparation advice. Use them with the full objectives, maintaining coverage across all four domains.
- Security Operations: inspect legitimate sample logs or tool output, identify what the records show and what they leave uncertain, and review the AI risks and governance in objective 1.6.
- Vulnerability Management: compare scanning methods and interpret supplied findings; practise priority decisions using stated exploitation, exposure and asset context.
- Incident Response: review the listed frameworks, process and evidence-handling topics, then explain a supplied scenario using its stated roles and constraints.
- Reporting and Communication: turn a finding into a short technical handover and an audience-appropriate summary. Separate known facts, unanswered questions and the requested next decision.
Facts come from CompTIA's official V4 and V3 certification pages, CompTIA's PBQ guidance and retake policy, and the CS0-004 V4 objectives document (a training-site-hosted copy).: CompTIA CySA+ CS0-004 V4 Exam Objectives (Document Version 2.0, training-site-hosted copy) — Test details, domain weights, objectives 1.1–4.2, accreditation and materials policy; CySA+ Certification V4 (New Version) | CompTIA — Exam details and V4 objectives summary
Worked practice: ranking a vulnerability queue
The objectives include exploitation, impact, asset context and scoring methods in prioritization. This original exercise supplies a fictional policy so there is a clear answer.
Read the policy and findings in the prompt before ranking them. The numbers are supplied severity values; no CVSS calculation or universal remediation rule is implied.
The ranking exercise uses a fictional policy invented for practice; it is not a CompTIA rule.
Original exercise: a fictional policy assigns priority 1 to confirmed active exploitation, priority 2 to internet-facing findings without confirmed active exploitation, and priority 3 to all others. Within one priority, the higher supplied severity goes first. A: severity 9.8, internal, no confirmed active exploitation. B: severity 8.1, internet-facing, confirmed active exploitation. C: severity 9.5, internet-facing, no confirmed active exploitation. Rank A, B and C, and explain each position.
Show the ranking and justification
B, then C, then A.
B is priority 1 because active exploitation is confirmed. C is priority 2 because it is internet-facing without confirmed active exploitation. A is priority 3 under the remaining rule. Severity only breaks a tie within a priority, so A's higher number does not move it ahead. This result follows from the supplied fictional policy; it is not a universal operational rule or a CompTIA scoring rule.
Facts come from CompTIA's official V4 and V3 certification pages, CompTIA's PBQ guidance and retake policy, and the CS0-004 V4 objectives document (a training-site-hosted copy).: CompTIA CySA+ CS0-004 V4 Exam Objectives (Document Version 2.0, training-site-hosted copy) — Test details, domain weights, objectives 1.1–4.2, accreditation and materials policy
Preparation pitfalls and a final checklist
Confirm your version, cover the matching objectives and practise the applied tasks before booking.
Review errors against the relevant objective and note which facts or steps you missed. A practice score or one completed lab does not guarantee exam readiness, so treat both as signals pointing to what to revisit.
- Confirm the booked code and language. For CS0-003, sit the English exam before December 22, 2026, or its Japanese, Portuguese or Spanish exam before March 23, 2027.
- Map any older resources to the objectives for your booked version and fill the gaps you find.
- Practise reading logs and scanner output, work through simulation-style tasks, and write concise findings.
- Explain a priority decision using the policy and evidence supplied, as in the exercise above.
- Each attempt requires payment; confirm the price and any retake coverage in your voucher or bundle with CompTIA.
Facts come from CompTIA's official V4 and V3 certification pages, CompTIA's PBQ guidance and retake policy, and the CS0-004 V4 objectives document (a training-site-hosted copy).: CySA+ Certification V4 (New Version) | CompTIA — Exam details and V4 objectives summary; CySA+ Certification V3 (Retiring Version) | CompTIA — Retirement dates, V3 exam details and objectives summary; CompTIA Certification Retake Policy | CompTIA IT Certifications — Waiting periods and per-attempt payment; Performance-Based Questions Overview | CompTIA IT Certifications — Simulation vs virtual PBQs, skip/return behavior; CompTIA CySA+ CS0-004 V4 Exam Objectives (Document Version 2.0, training-site-hosted copy) — Test details, domain weights, objectives 1.1–4.2, accreditation and materials policy; Cybersecurity Analyst+ (CySA+) Certification | CompTIA — Catalog page confirming V4 current and V3 retirement dates; Performance-Based Questions FAQs | CompTIA Blog — Reset behavior, multiple valid paths, partial credit
Facts come from CompTIA's official V4 and V3 certification pages, CompTIA's PBQ guidance and retake policy, and the CS0-004 V4 objectives document (a training-site-hosted copy).
Format, scoring, retirement and retake facts verified September 14, 2026 against retrieved CompTIA sources.:
- CySA+ Certification V4 (New Version) | CompTIA
- CySA+ Certification V3 (Retiring Version) | CompTIA
- Cybersecurity Analyst+ (CySA+) Certification | CompTIA
- Performance-Based Questions Overview | CompTIA IT Certifications
- Performance-Based Questions FAQs | CompTIA Blog
- CompTIA Certification Retake Policy | CompTIA IT Certifications
- CompTIA CySA+ CS0-004 V4 Exam Objectives (Document Version 2.0, training-site-hosted copy)
