About This Study Plan
This 30-day study plan breaks the CYSA (CySA+) exam preparation into 4 focused study sessions with 16 actionable tasks. The plan covers all 4 exam domains — Security Operations, Vulnerability Management, Incident Response and Management, Reporting and Communication — ensuring complete coverage. Structured 30-day study plan for CompTIA CySA+ (CS0-003).
Prerequisites
- Security+ or 2+ years SOC experience
- 2–3 hours per day
Study Schedule
- Days 1–2: SIEM architecture, log sources, and alert configuration
- Days 3–4: Threat intelligence, IOC analysis, STIX/TAXII
- Days 5–6: Network and endpoint monitoring tools
- Day 7: Threat hunting techniques and security operations quiz
- Days 8–9: Vulnerability scanning tools, configuration, and scheduling
- Days 10–11: CVSS scoring, prioritization, and remediation planning
- Days 12–13: Application security testing (SAST, DAST, IAST)
- Day 14: Patch management and compensating controls quiz
- Days 15–16: IR lifecycle, playbooks, and containment strategies
- Days 17–18: Digital forensics, evidence handling, chain of custody
- Days 19–20: Malware analysis basics, sandboxing, IOC extraction
- Day 21: Reporting, metrics, and communication quiz
- Days 22–23: Full practice exam #1 + review
- Days 24–25: Log analysis PBQ practice
- Days 26–27: Full practice exam #2 + weak areas
- Days 28–30: MITRE ATT&CK review, flashcards, and rest
Study Tips
Build a home SIEM (Wazuh or ELK) for hands-on log analysis practice.
CySA+ is analysis-heavy — practice interpreting data, not just memorizing facts.
Know the difference between IOCs and IOAs.
Recommended CompTIA Study Resources
Supplement this study plan with the official CompTIA CertMaster labs and practice tests. Download the free exam objectives PDF from CompTIA's website and use it as a checklist — cross off each objective as you master it. Professor Messer's free video series covers every CompTIA exam objective and is widely regarded as one of the best free resources available.
Ready to Practice?
Put your study plan into action with CySA+ practice questions.