Browse the reference notes below to support your lessons and practical exercises.
Reference Hub
CompTIA CySA+ (v3) Docs
Browse the objective domains, curated references, and supporting knowledge base content from one place.
Cheat Sheet
Quick-review reference for domains, weights, and key concepts.
Textbook Map
Jump from chapters to the relevant CySA objective domains.
Website Links
Browse source references and study links grouped by topic.
Objective domains
Exam Information
OverviewCore details for the CompTIA CySA+ (v3) exam format, timing, scoring, and objective weighting.
Security Operations
33%Explaining system and network architecture, malicious activity indicators, tools and techniques, threat intelligence and hunting, and process improvement.
Vulnerability Management
30%Covering vulnerability scanning strategy, assessment output analysis, prioritization, mitigation controls, and response workflows.
Incident Response Management
20%Explaining attack methodology frameworks, incident response activities, and the incident management life cycle.
Reporting and Communication
17%Focusing on clear vulnerability and incident reporting, escalation, stakeholder communication, and measurable outcomes.
Knowledge base
7 docsChange management, procurement, and disposal are critical processes in IT governance that ensure security, compliance, and operational efficiency throughout the asset lifecycle. This lesson covers implementing robust change control procedures and secure asset lifecycle management practices.
CVSS Scoring and the National Vulnerability DatabaseThe Common Vulnerability Scoring System (CVSS) provides a standardized way to rate the severity of security vulnerabilities. The National Vulnerability Database (NVD) applies CVSS as part of its public catalog, enabling defenders to prioritize remediation, drive patch management, and communicate risk. This lesson explains how CVSS vectors are constructed, how to interpret scores, and how to leverage the NVD for actionable intelligence.
Domain-based Message Authentication, Reporting, and Conformance (DMARC)Domain-based Message Authentication, Reporting, and Conformance (DMARC) is an email authentication policy and reporting framework that builds on SPF and DKIM to help domain owners detect and prevent spoofing. This lesson explains how DMARC works, how to interpret its reports, and how to move from passive monitoring to an enforcement policy that protects brands, customers, and internal users against phishing campaigns.
Linux File Permissions & Access ControlLinux file permissions are a fundamental security mechanism that controls who can read, write, and execute files and directories. This lesson covers standard Unix permissions, special permissions, Access Control Lists (ACLs), and practical security implementations.
OWASP Top Ten Web Application Security RisksThe Open Worldwide Application Security Project (OWASP) publishes vendor-neutral guidance to help teams identify, prioritize, and remediate software security weaknesses. This lesson explains the OWASP Top Ten risks, why they matter to modern web applications, and how to integrate the guidance into secure development and operations workflows.
Windows 11 File Sharing & Network SharesFile sharing in Windows 11 allows you to share folders and files with other computers on your network. This lesson covers creating shares, managing permissions, and understanding the security implications of network sharing.
Windows 11 Offline Account EnrollmentModern Windows 11 builds push Microsoft account sign-in during the Out-Of-Box Experience (OOBE). For lab environments, privacy-focused deployments, or gold-image creation, administrators often need a fully offline local administrator profile. This lesson captures the supported `ms-cxh:localonly` workflow used to bypass Microsoft account requirements during setup without hacking installation media.