CySA+ Domain 1: Security Operations
Domain 1.0: Security Operations · 34% of the exam
The largest domain on CompTIA's new CySA+ V4 exam: all 6 objectives (1.1–1.6), from logging architecture and indicator analysis through the analyst toolkit, threat hunting, SOC process improvement, and the brand-new AI objective. Follow analyst Rafael Ortiz through a working hospital SOC, with hand-built diagrams, real tool output, and 120 exam-style questions.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
34% of your exam score
Domain 1.0 is worth 34% of the CS0-004 exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official CompTIA CySA+ objectives 1.1–1.6: 36 in-depth topics with worked scenarios and exam tips, in a 184-page guide you'll actually finish.
120 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The analyst's cert, freshly rewritten
CySA+ is the step past Security+ into SOC and vulnerability analyst roles, and CS0-004 is the brand-new V4 blueprint, including the first AI objective CompTIA has put on a CySA+ exam.
Serving, transitioning, or a military spouse?
CySA+ appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 1.1, Architecture for analysts, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Explain concepts related to system and network architecture in security operations
Logging that can be trusted, operating systems you can read, cloud and container architectures that change what a host can see, identity as the new perimeter, and the operational technology that breaks every rule the rest of this guide teaches.
Rafael Ortiz has been a level-two analyst at Meridian Health for eight months — nine hospitals, sixty clinics, roughly fourteen thousand staff, and an estate that runs from a brand-new Kubernetes platform down to infusion pumps whose vendor went out of business in 2019. On his second week his manager, Nadia Okonkwo, gave him a piece of advice he has repeated to every new analyst since: before you investigate anything, know what your architecture is capable of telling you.
That is what this objective is really about. An architect asks how to build the system. An analyst asks a narrower and more urgent question: when something goes wrong here, what evidence will exist, how much of it can I trust, and where are the places an adversary could operate without leaving any? Everything below is architecture seen from that angle.
1.1 is an “explain” objective, not a “given a scenario” one, so questions tend to test whether you can define a concept and distinguish it from its neighbours — ZTNA versus SASE, agent versus agentless visibility, IT versus OT priorities. Expect definition and comparison items rather than long investigative stems. The scenario work comes in 1.2 and 1.3.
Logging concepts: five properties, tested separately
Logs are the substrate of every other skill on this exam. CompTIA breaks logging into five properties, and it is worth learning them as five separate failure modes, because that is how they appear in questions — a stem describes one thing going wrong and asks you to name it.
| Property | What it means | How it fails |
|---|---|---|
| Ingestion | Getting events from the source into the platform — agents, forwarders, syslog, API pulls, cloud-native streams. | A source silently stops sending. The dashboard looks calm because absence of alerts and absence of data render identically. |
| Configuration | What the source is set to record, and at what verbosity. Default logging is almost never sufficient for investigation. | The event you need was never enabled. Windows does not audit process creation by default; command-line capture is a separate setting again. |
| Integrity and security | Proving the record was not altered, and preventing tampering — write-once storage, hashing, restricted access, forwarding off-host immediately. | An attacker with local administrator rights clears the log. If the only copy was on the compromised host, the evidence is gone. |
| Time synchronization | A common, accurate clock across every source, so events from different systems can be placed in one order. | Two sources disagree by six minutes. Your timeline shows the response happening before the attack. |
| Retention | How long records are kept, driven by regulation, contract and investigative need. | Dwell time exceeded retention. The intrusion started in March; logs go back sixty days. |
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 120-question bank. Tap an answer for instant feedback and the explanation.
From module 1.1 · Architecture for analysts
1. A SOC dashboard has shown no alerts from the domain controllers for two days. The controllers are running normally and users are authenticating without issue. Which logging property has most likely failed?
From module 1.2 · Reading the indicators
1. A host connects outbound to the same address every 3,600 seconds with a payload of 184 bytes each time, continuing across reboots and while no user is logged in. Which activity does this indicate?
From module 1.3 · The analyst's toolkit
1. An analyst needs to determine which process on a host initiated a suspicious outbound connection. Which tool answers this most directly?
117 more questions like these are waiting inside.
What's inside
- 36 in-depth topics across 6 modules, mapped to objectives 1.1–1.6
- 120 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- Objective 1.6: AI in security operations, new in CS0-004
- A running SOC scenario that ties all six objectives together
- Complete CySA+ acronym & key-term reference
- 184-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 1.120 Qs
Architecture for analysts
Explain concepts related to system and network architecture in security operations.
Log ingestion, integrity & retentionTime synchronization & correlationCloud native, virtualization & containerizationZero Trust Network Architecture (ZTNA) & SASEIAM, PAM & secrets managementOT, ICS & SCADA constraints - 1.220 Qs
Reading the indicators
Given a scenario, analyze indicators of potential malicious activity.
Beaconing & C2 traffic patternsLOLBins and living-off-the-landEnumeration & rogue devicesImpossible travel & IAM compromiseBusiness email compromise (BEC)Data exfiltration indicators - 1.320 Qs
The analyst's toolkit
Given a scenario, use tools to determine malicious activity.
Wireshark, tcpdump & ZeekSnort & Suricata rulesSIEM correlation & queriesEDR/XDR vs. packet captureSandboxing, Strings, VirusTotal & YARACyberChef, regex & email analysis - 1.420 Qs
Threat intelligence & hunting
Explain threat intelligence and threat-hunting concepts.
Pyramid of PainAtomic vs. behavioral IoCsConfidence: timeliness, relevance, accuracyOSINT vs. closed-source intelligenceMITRE ATT&CK & heat mapsSTRIDE & cyber deception - 1.520 Qs
Efficiency & process improvement
Explain the importance of efficiency and process improvement in security operations.
Playbooks vs. runbooksSOAR & orchestrationInfrastructure as code (IaC)Data enrichmentRule & alert tuningAPIs, webhooks & plug-ins - 1.620 Qs
AI in security operations
Summarize concepts related to the use of AI in security operations.
Hallucinations & verificationData exposure through promptsModel poisoningMalicious promptsAI usage policies & complianceAssistive SOC use cases

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CySA+ Collection.
Every domain of the exam, including this guide, for $59, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CS0-004 exam?
Yes. The guide is mapped module-by-module to the official CompTIA CySA+ objectives (1.1–1.6), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 120 practice questions, plus a 184-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 1.0 (34% of the exam). To prepare for the whole exam, the Complete CySA+ Collection bundles all 4 domains for $59, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 34% of the exam, for $19.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide