Skip to content
CompTIA CySA+ · CS0-004

CySA+ Domain 1: Security Operations

Domain 1.0: Security Operations · 34% of the exam

The largest domain on CompTIA's new CySA+ V4 exam: all 6 objectives (1.1–1.6), from logging architecture and indicator analysis through the analyst toolkit, threat hunting, SOC process improvement, and the brand-new AI objective. Follow analyst Rafael Ortiz through a working hospital SOC, with hand-built diagrams, real tool output, and 120 exam-style questions.

6 modules · 36 topics 184-page PDF 120 practice questions
Read a free sample By the author of 51 Pluralsight courses · 4.6/5 from 2,007 ratings
Best value
$29/ month

All study guides, current and every new one.

or own the whole exam
$59one-time · all 4 domains
or just this guide
$19.95one-time · lifetime access
  • Interactive online guide
  • Downloadable PDF
  • Lifetime updates
  • 30-day money-back guarantee

Secure checkout via Stripe · no account needed · instant access

34% of your exam score

Domain 1.0 is worth 34% of the CS0-004 exam. Walk in having mastered it, not hoping it doesn't come up.

Every objective, nothing extra

Built line by line from the official CompTIA CySA+ objectives 1.1–1.6: 36 in-depth topics with worked scenarios and exam tips, in a 184-page guide you'll actually finish.

120 exam-style questions

Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.

The analyst's cert, freshly rewritten

CySA+ is the step past Security+ into SOC and vulnerability analyst roles, and CS0-004 is the brand-new V4 blueprint, including the first AI objective CompTIA has put on a CySA+ exam.

Serving, transitioning, or a military spouse?

CySA+ appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →

Read a real excerpt, free

This is the actual opening of Module 1.1, Architecture for analysts, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.

Objective 1.1

Explain concepts related to system and network architecture in security operations

Logging that can be trusted, operating systems you can read, cloud and container architectures that change what a host can see, identity as the new perimeter, and the operational technology that breaks every rule the rest of this guide teaches.

Rafael Ortiz has been a level-two analyst at Meridian Health for eight months — nine hospitals, sixty clinics, roughly fourteen thousand staff, and an estate that runs from a brand-new Kubernetes platform down to infusion pumps whose vendor went out of business in 2019. On his second week his manager, Nadia Okonkwo, gave him a piece of advice he has repeated to every new analyst since: before you investigate anything, know what your architecture is capable of telling you.

That is what this objective is really about. An architect asks how to build the system. An analyst asks a narrower and more urgent question: when something goes wrong here, what evidence will exist, how much of it can I trust, and where are the places an adversary could operate without leaving any? Everything below is architecture seen from that angle.

Exam focus · What 1.1 actually tests

1.1 is an “explain” objective, not a “given a scenario” one, so questions tend to test whether you can define a concept and distinguish it from its neighbours — ZTNA versus SASE, agent versus agentless visibility, IT versus OT priorities. Expect definition and comparison items rather than long investigative stems. The scenario work comes in 1.2 and 1.3.

Logging concepts: five properties, tested separately

Logs are the substrate of every other skill on this exam. CompTIA breaks logging into five properties, and it is worth learning them as five separate failure modes, because that is how they appear in questions — a stem describes one thing going wrong and asks you to name it.

PropertyWhat it meansHow it fails
IngestionGetting events from the source into the platform — agents, forwarders, syslog, API pulls, cloud-native streams.A source silently stops sending. The dashboard looks calm because absence of alerts and absence of data render identically.
ConfigurationWhat the source is set to record, and at what verbosity. Default logging is almost never sufficient for investigation.The event you need was never enabled. Windows does not audit process creation by default; command-line capture is a separate setting again.
Integrity and securityProving the record was not altered, and preventing tampering — write-once storage, hashing, restricted access, forwarding off-host immediately.An attacker with local administrator rights clears the log. If the only copy was on the compromised host, the evidence is gone.
Time synchronizationA common, accurate clock across every source, so events from different systems can be placed in one order.Two sources disagree by six minutes. Your timeline shows the response happening before the attack.
RetentionHow long records are kept, driven by regulation, contract and investigative need.Dwell time exceeded retention. The intrusion started in March; logs go back sixty days.
The guide continues for 184 pagesKeep reading: unlock the full guide

Not ready to buy? Read it later.

We'll email you a free sample of this guide as a PDF, no purchase needed.

Try 3 sample questions

Pulled straight from the guide's 120-question bank. Tap an answer for instant feedback and the explanation.

From module 1.1 · Architecture for analysts

  1. 1. A SOC dashboard has shown no alerts from the domain controllers for two days. The controllers are running normally and users are authenticating without issue. Which logging property has most likely failed?

From module 1.2 · Reading the indicators

  1. 1. A host connects outbound to the same address every 3,600 seconds with a payload of 184 bytes each time, continuing across reboots and while no user is logged in. Which activity does this indicate?

From module 1.3 · The analyst's toolkit

  1. 1. An analyst needs to determine which process on a host initiated a suspicious outbound connection. Which tool answers this most directly?

117 more questions like these are waiting inside.

What's inside

  • 36 in-depth topics across 6 modules, mapped to objectives 1.1–1.6
  • 120 exam-style practice questions with instant feedback
  • Full answer key explaining why every distractor is wrong
  • Objective 1.6: AI in security operations, new in CS0-004
  • A running SOC scenario that ties all six objectives together
  • Complete CySA+ acronym & key-term reference
  • 184-page downloadable PDF for offline study and printing
  • Lifetime updates as the exam evolves

The modules, mapped to the objectives

  1. 1.1

    Architecture for analysts

    Explain concepts related to system and network architecture in security operations.

    20 Qs
    Log ingestion, integrity & retentionTime synchronization & correlationCloud native, virtualization & containerizationZero Trust Network Architecture (ZTNA) & SASEIAM, PAM & secrets managementOT, ICS & SCADA constraints
  2. 1.2

    Reading the indicators

    Given a scenario, analyze indicators of potential malicious activity.

    20 Qs
    Beaconing & C2 traffic patternsLOLBins and living-off-the-landEnumeration & rogue devicesImpossible travel & IAM compromiseBusiness email compromise (BEC)Data exfiltration indicators
  3. 1.3

    The analyst's toolkit

    Given a scenario, use tools to determine malicious activity.

    20 Qs
    Wireshark, tcpdump & ZeekSnort & Suricata rulesSIEM correlation & queriesEDR/XDR vs. packet captureSandboxing, Strings, VirusTotal & YARACyberChef, regex & email analysis
  4. 1.4

    Threat intelligence & hunting

    Explain threat intelligence and threat-hunting concepts.

    20 Qs
    Pyramid of PainAtomic vs. behavioral IoCsConfidence: timeliness, relevance, accuracyOSINT vs. closed-source intelligenceMITRE ATT&CK & heat mapsSTRIDE & cyber deception
  5. 1.5

    Efficiency & process improvement

    Explain the importance of efficiency and process improvement in security operations.

    20 Qs
    Playbooks vs. runbooksSOAR & orchestrationInfrastructure as code (IaC)Data enrichmentRule & alert tuningAPIs, webhooks & plug-ins
  6. 1.6

    AI in security operations

    Summarize concepts related to the use of AI in security operations.

    20 Qs
    Hallucinations & verificationData exposure through promptsModel poisoningMalicious promptsAI usage policies & complianceAssistive SOC use cases
Chris Rees

About the author

Chris Rees

Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.

More about Chris
All 4 CS0-004 domains

Sitting the whole exam? Get the Complete CySA+ Collection.

Every domain of the exam, including this guide, for $59, one time.

See everything inside

Questions, answered

Do I need an account to buy?

No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.

Is this up to date with the real CS0-004 exam?

Yes. The guide is mapped module-by-module to the official CompTIA CySA+ objectives (1.1–1.6), and lifetime updates are included, so as the exam evolves your guide does too.

What exactly do I get?

Instant access to the interactive online guide with all 120 practice questions, plus a 184-page PDF you can download, print, and keep forever.

Do I need the other domains too?

This guide covers Domain 1.0 (34% of the exam). To prepare for the whole exam, the Complete CySA+ Collection bundles all 4 domains for $59, less than the price of three guides.

What if it isn't for me?

Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.

Who wrote it?

Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.

Be ready for 34% of the exam, for $19.95

Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.

Get the guide

Share this guide