Course ID: #N/A

CompTIA Cybersecurity Analyst CySA+ (CS0-004)

Duration: 5 days Dates: 12 October 2026 11 January 2027 12 April 2027 12 July 2027

CompTIA CySA+ is aimed at professionals who detect, analyse and respond to threats in a security operations centre. The course follows the current CS0-004 exam version with its four domains: Security Operations, Vulnerability Management, Incident Response, and Reporting and Communication – including AI in security operations, EPSS-based prioritisation, ZTNA and SASE. The course prepares you for the CS0-004 exam (certification «CompTIA Cybersecurity Analyst (CySA+)»).

Security Operations

  • System and network architecture in security operations: architecture components, identity concepts, logging; Zero Trust Network Access (ZTNA) and SASE, cloud and hybrid environments
  • Analyse indicators of malicious activity in networks, on endpoints, in the cloud and in identity systems
  • Detection tools: SIEM, EDR and XDR, packet analysis, threat intelligence platforms
  • Threat intelligence and threat hunting: frameworks, data sources and methods
  • Efficiency and process improvement: automation with SOAR, workflows, automated threat intelligence processes
  • AI in security operations: use cases, risks and governance

Vulnerability Management

  • Select and implement suitable scanning methods for systems, networks and applications
  • Analyse results from vulnerability scans and assessment tools and classify security gaps
  • Prioritise and remediate vulnerabilities based on risk: scoring systems such as EPSS, threat intelligence and business context
  • Software supply chain and Software Bill of Materials (SBOM)
  • Control types, policies, risks and compliance in vulnerability management

Incident Response and Incident Management

  • Models for attack methods: MITRE ATT&CK and the Cyber Kill Chain
  • The incident response process: preparation, detection, analysis, containment, eradication and recovery
  • Incident handling techniques: triage, handling evidence, escalation, remediation and root cause analysis

Reporting and Communication

  • Vulnerability management reports and dashboards, stakeholder communication and escalation for security events
  • Incident documentation, post-incident reviews and metrics such as detection time, response time and remediation effectiveness
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/10/12, 2027/01/11, 2027/04/12, 2027/07/12, flexibel, auf Anfrage

Security and SOC analysts, incident responders, vulnerability and threat intelligence analysts, and security engineers who detect threats and handle security incidents.

You should have knowledge at CompTIA Security+ level and practical experience in IT security. CompTIA recommends around four years of experience as a SOC or vulnerability analyst for the exam.

After the course you will be able to:

  • detect and investigate suspicious activity in networks, on endpoints, in the cloud and in identity systems
  • use SIEM, EDR and threat intelligence platforms for analysis and threat hunting
  • scan for vulnerabilities, evaluate results and prioritise them based on risk
  • handle security incidents in a structured way following an incident response process
  • assess the opportunities and risks of AI and automation in security operations
  • communicate findings and risks clearly in reports and dashboards

CHF3'220 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation