Reference Hub

CompTIA CySA+ (v3) Docs

Browse the objective domains, curated references, and supporting knowledge base content from one place.

5 objective sections7 knowledge documents

Cheat Sheet

Quick-review reference for domains, weights, and key concepts.

Textbook Map

Jump from chapters to the relevant CySA objective domains.

Website Links

Browse source references and study links grouped by topic.

Objective domains

Knowledge base

7 docs

Browse the reference notes below to support your lessons and practical exercises.

Change Management and IT Asset Procurement & Disposal

Change management, procurement, and disposal are critical processes in IT governance that ensure security, compliance, and operational efficiency throughout the asset lifecycle. This lesson covers implementing robust change control procedures and secure asset lifecycle management practices.

CVSS Scoring and the National Vulnerability Database

The Common Vulnerability Scoring System (CVSS) provides a standardized way to rate the severity of security vulnerabilities. The National Vulnerability Database (NVD) applies CVSS as part of its public catalog, enabling defenders to prioritize remediation, drive patch management, and communicate risk. This lesson explains how CVSS vectors are constructed, how to interpret scores, and how to leverage the NVD for actionable intelligence.

Domain-based Message Authentication, Reporting, and Conformance (DMARC)

Domain-based Message Authentication, Reporting, and Conformance (DMARC) is an email authentication policy and reporting framework that builds on SPF and DKIM to help domain owners detect and prevent spoofing. This lesson explains how DMARC works, how to interpret its reports, and how to move from passive monitoring to an enforcement policy that protects brands, customers, and internal users against phishing campaigns.

Linux File Permissions & Access Control

Linux file permissions are a fundamental security mechanism that controls who can read, write, and execute files and directories. This lesson covers standard Unix permissions, special permissions, Access Control Lists (ACLs), and practical security implementations.

OWASP Top Ten Web Application Security Risks

The Open Worldwide Application Security Project (OWASP) publishes vendor-neutral guidance to help teams identify, prioritize, and remediate software security weaknesses. This lesson explains the OWASP Top Ten risks, why they matter to modern web applications, and how to integrate the guidance into secure development and operations workflows.

Windows 11 File Sharing & Network Shares

File sharing in Windows 11 allows you to share folders and files with other computers on your network. This lesson covers creating shares, managing permissions, and understanding the security implications of network sharing.

Windows 11 Offline Account Enrollment

Modern Windows 11 builds push Microsoft account sign-in during the Out-Of-Box Experience (OOBE). For lab environments, privacy-focused deployments, or gold-image creation, administrators often need a fully offline local administrator profile. This lesson captures the supported `ms-cxh:localonly` workflow used to bypass Microsoft account requirements during setup without hacking installation media.