CySA+ Domain 2: Vulnerability Management
Domain 2.0: Vulnerability Management · 26% of the exam
The second-largest domain on CySA+ V4: all 4 objectives (2.1–2.4), from asset inventory and scan selection through reading tool output critically, prioritizing on exploitation evidence rather than severity, and the control and risk vocabulary that makes a program defensible. Follow vulnerability lead Dev Sharma as he rebuilds a hospital's program from 61,000 findings down to work that fits.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
26% of your exam score
Domain 2.0 is worth 26% of the CS0-004 exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official CompTIA CySA+ objectives 2.1–2.4: 26 in-depth topics with worked scenarios and exam tips, in a 124-page guide you'll actually finish.
80 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The analyst's cert, freshly rewritten
CySA+ is the step past Security+ into SOC and vulnerability analyst roles, and CS0-004 is the brand-new V4 blueprint, including the first AI objective CompTIA has put on a CySA+ exam.
Serving, transitioning, or a military spouse?
CySA+ appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 2.1, Choosing the scan, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Given a scenario, implement the appropriate vulnerability scanning method
Asset inventory as the foundation, the planning constraints that decide when you may scan, and the paired scan types the exam asks you to choose between.
Dev Sharma runs vulnerability management at Meridian Health. When he took the role, the programme reported 94% scan coverage every month, and the number was meaningless — 94% of the assets in a spreadsheet last reconciled two years earlier. The first genuine finding of his tenure was not a vulnerability. It was 1,400 devices nobody had a record of, including a clinical research subnet running its own domain.
That is why this objective opens where it does.
2.1 is a “given a scenario” objective, and its questions almost always describe a constraint — a maintenance window, a fragile device, a regulation, a network you cannot reach — then ask which scan fits. Read for the constraint first. It eliminates two options before you have finished the stem.
Asset inventory: the denominator
An asset inventory is the authoritative record of what the organization owns and is responsible for: hardware, software, cloud resources, ownership, business criticality and data sensitivity. Every metric in vulnerability management is a fraction, and the inventory is the denominator. Without it, “96% of systems patched” is a statement about the systems you happen to know about.
Inventory is built by reconciling sources that each see part of the estate and none see all of it:
The interesting output of reconciliation is not the list — it is the disagreements. A host answering probes that appears in no inventory is a shadow asset. A host in the CMDB that has not responded in ninety days is either decommissioned without a record or turned off in a cupboard waiting to be turned back on unpatched. Both are findings, and neither is a vulnerability in the scanner's sense.
Planning considerations
Six constraints are named in the objective. Each one is a reason a technically ideal scan is not the scan you are allowed to run.
| Consideration | The question it forces | How it shapes the scan |
|---|---|---|
| Scheduling | When may this run? | Maintenance windows, month-end freezes, clinical peak hours. A scan that has to finish by 06:00 constrains depth and concurrency. |
| Operations | What breaks if we are wrong? | Fragile devices, legacy stacks and safety-critical systems push you toward passive or credentialed-but-gentle scanning, or out of active scanning altogether. |
| Performance | What load can the network and targets absorb? | Concurrency, packet rate and plugin depth all trade completeness against impact. Saturating a link during business hours is a self-inflicted outage. |
| Sensitivity levels | What will the scanner see and store? | Credentialed scans of systems holding regulated data mean scan results themselves become sensitive — and the credentials used become a high-value target. |
| Segmentation | Can we even reach it? | A segmented network needs a scanner inside the segment, or an authorized path through. Otherwise you are measuring the firewall, not the hosts. |
| Regulatory requirements | What are we obliged to do? | Frequency, scope and evidence are mandated: PCI DSS requires quarterly internal and external scanning, with external scans by an approved vendor. |
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 80-question bank. Tap an answer for instant feedback and the explanation.
From module 2.1 · Choosing the scan
1. A vulnerability management programme reports 94% scan coverage. The asset inventory it measures against was last reconciled two years ago. What is the problem?
From module 2.2 · Reading the output
1. An Nmap scan reports port 3306/tcp as closed. What has the analyst learned?
From module 2.3 · Prioritize and mitigate
1. Vulnerability A: CVSS 9.8, no known exploitation, EPSS 0.3%, on an isolated lab host. Vulnerability B: CVSS 6.5, listed in CISA KEV, on an internet-facing server. Which is remediated first?
77 more questions like these are waiting inside.
What's inside
- 26 in-depth topics across 4 modules, mapped to objectives 2.1–2.4
- 80 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- Real Nmap, Nessus, Nikto and Checkov output, read line by line
- Complete CySA+ acronym & key-term reference
- 124-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 2.120 Qs
Choosing the scan
Given a scenario, implement the appropriate vulnerability scanning method.
Asset inventory & coverageInternal vs. external scanningAgent vs. agentlessCredentialed vs. non-credentialedPassive vs. activePCI DSS, CIS Benchmarks, ISO 27000 - 2.220 Qs
Reading the output
Given a scenario, analyze output from vulnerability assessment tools.
Nmap states: open, closed, filteredMasscan & Angry IP ScannerBurp Suite, ZAP & NiktoNessus, OpenVAS & NucleiTrivy, Checkov, ScoutSuite & ProwlerBAS: Atomic Red Team & Caldera - 2.320 Qs
Prioritize and mitigate
Given a scenario, analyze data to prioritize and mitigate vulnerabilities.
CVSS vs. EPSS vs. active exploitationContext: internal, external, isolatedAsset value & business impactTrue/false positives & negativesCompensating controls & exceptionsValidation of remediation - 2.420 Qs
Controls, risk & governance
Explain concepts related to control types, risks, and vulnerability management.
Control types vs. control functionsInherent, residual risk & risk appetiteAccept, transfer, avoid, mitigateSAST vs. DASTSAMM & secure developmentSupply chain, SCA & SBOM

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CySA+ Collection.
Every domain of the exam, including this guide, for $59, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CS0-004 exam?
Yes. The guide is mapped module-by-module to the official CompTIA CySA+ objectives (2.1–2.4), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 80 practice questions, plus a 124-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 2.0 (26% of the exam). To prepare for the whole exam, the Complete CySA+ Collection bundles all 4 domains for $59, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 26% of the exam, for $19.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide