Skip to content
A New Name. Same Commitment to Excellence. → Learn More about the Rebrand
💡Get 10% Off Further Education Courses! Use Code CARE10 before 30th September. → Apply Now
💡Get 10% Off Classroom & Live Online Diplomas! Use Code DIPLOMA10 before 30th September..
💡Get 10% Off On-Demand Professional Diplomas! Use Code DEMAND10 before 30th September..

CompTIA CySA+ (Cybersecurity Analyst)

Intake Autumn
Start Date Tuesday 8th September 2026
Duration 10 weeks, 1 evening per week from 6pm to 9pm | 5 Saturdays, 9.30am – 3.30pm
Learning Mode Live Online
Lecturer Contact 60 Hours
Payment Options
Payment Plan Available

This 10-week course develops the practical analytical skills required to detect, investigate, and respond to cybersecurity threats in modern organisations. Aligned with the CompTIA CySA+ (CS0-004) certification objectives, it covers security operations, threat intelligence and hunting, vulnerability management, incident response, and professional reporting. Learners work with realistic security data and defensive tools across endpoint, network, cloud, and hybrid environments. The course also addresses automation, artificial intelligence (AI) in security operations, and Zero Trust concepts, culminating in an applied investigation and incident-response portfolio.

CompTIA CySA+ (Cybersecurity Analyst)
Live Online

Live online training with real-time instructor-student interaction.

Payment plans available
HOME / CompTIA - CompTIA CySA+ (Cybersecurity Analyst)

Course Details

Learners will need a personal laptop or PC capable of running practical security tools and virtual machines. A working knowledge of computer networks, Windows and Linux operating systems, TCP/IP, and fundamental cybersecurity concepts is strongly recommended.

The course is designed for learners progressing beyond introductory cybersecurity study or working toward a cybersecurity analyst role. Knowledge equivalent to CompTIA Network+ and Security+ is beneficial. Previous security operations centre (SOC) experience is not required for course participation, although regular hands-on lab work and independent study will be essential.

Week 1: The Cybersecurity Analyst and Security Operations

This part of the course introduces the cybersecurity analyst role, SOC workflows, governance, risk, and the CySA+ exam domains. Learners review security architecture across on-premises, cloud, hybrid, operational technology, and Zero Trust environments, and identify the telemetry required for effective monitoring and investigation.

Week 2: Security Monitoring, Logging and Data Analysis

This part of the course focuses on collecting, normalising, and analysing security data. It covers system and application logs, network traffic, identity events, cloud telemetry, data formats, and time synchronisation. Learners use security information and event management (SIEM) concepts to correlate events, investigate alerts, and distinguish normal activity from potential compromise.

Week 3: Threat Intelligence, Threat Hunting and Adversary Behaviour

This part of the course examines threat intelligence sources, indicators of compromise, adversary tactics, techniques, and procedures, and threat-modelling frameworks. Learners develop hypotheses, perform structured threat hunts, assess intelligence quality, and use behavioural evidence to identify suspicious activity.

Week 4: Detection and Analysis of Malicious Activity

This part of the course develops practical skills in analysing endpoint, network, email, web, identity, and cloud indicators. Learners interpret packet captures and logs, examine suspicious files and processes, and apply SIEM, endpoint detection and response (EDR), extended detection and response (XDR), and sandboxing concepts to validate and prioritise alerts.

Week 5: Vulnerability Discovery and Assessment

This part of the course introduces the vulnerability management lifecycle. It covers asset discovery, vulnerability scanning, configuration assessment, application and cloud testing, common scoring systems, scanner limitations, and the interpretation of technical findings. Learners perform controlled assessments and distinguish true positives, false positives, and environmental exceptions.

Week 6: Vulnerability Prioritisation and Remediation

This part of the course focuses on risk-based vulnerability analysis. Learners combine technical severity, threat intelligence, exploitability, asset criticality, exposure, and business impact to prioritise remediation. The week also covers compensating controls, patch and configuration management, validation, exception handling, and remediation tracking.

Week 7: Incident Response and Digital Investigation

This part of the course covers preparation, detection, analysis, containment, eradication, recovery, and post-incident activity. Learners practise triage, evidence preservation, timeline construction, scoping, escalation, and coordination while considering legal, regulatory, privacy, and business requirements.

Week 8: Response Automation, Cloud Security and AI in the SOC

This part of the course examines security orchestration, automation and response (SOAR), playbooks, scripting, APIs, and workflow optimisation. It also addresses cloud-native and hybrid security monitoring and the responsible use of AI for analysis, correlation, documentation, and automation, including risks such as data exposure, hallucination, model manipulation, and weak governance.

Week 9: Reporting, Communication and Security Metrics

This part of the course develops the communication skills required of a cybersecurity analyst. Learners produce vulnerability and incident reports for technical and non-technical stakeholders, define meaningful metrics and key performance indicators, document root causes and lessons learned, and communicate remediation priorities, risk, and escalation decisions.

Week 10: Integrated SOC Investigation and Exam Preparation

This part of the course integrates the four CySA+ domains through a realistic SOC case study. Learners analyse security telemetry, investigate malicious activity, prioritise vulnerabilities, recommend response actions, and present an evidence-based report. The course concludes with scenario-based revision, performance-based question practice, a mock examination, and guidance on cybersecurity analyst career pathways.

Learners will be evaluated through two applied assessments aligned with the CompTIA CySA+ (CS0-004) domains, together with scenario-based quizzes and a final mock examination. The course prepares learners for the knowledge and practical skills tested by CySA+; the external CompTIA certification examination and exam voucher are separate unless explicitly included by the training provider.

Assessment 1: Security Operations and Vulnerability Management Portfolio

  • Collect, interpret, and correlate security events from endpoint, network, identity, and cloud sources.
  • Analyse indicators of compromise and document an evidence-based alert triage decision.
  • Develop and execute a structured threat-hunting hypothesis using relevant intelligence.
  • Perform a controlled vulnerability assessment and evaluate the quality of the findings.
  • Prioritise vulnerabilities using severity, exploitability, asset criticality, and business impact.
  • Recommend remediation actions, compensating controls, validation steps, and realistic timelines.
  • Produce concise technical documentation suitable for SOC and vulnerability-management workflows.
  • Assess competencies in Security Operations (34%) and Vulnerability Management (26%) of the CS0-004 exam objectives.

 

Assessment 2: Incident Investigation, Response and Communication Project

  • Investigate a realistic incident using logs, alerts, network evidence, and endpoint artefacts.
  • Establish the incident scope, timeline, affected assets, attack path, and likely root cause.
  • Recommend and justify containment, eradication, recovery, and monitoring actions.
  • Preserve and document evidence while considering legal, regulatory, privacy, and business requirements.
  • Develop an incident-response report, executive summary, escalation record, and lessons-learned review.
  • Demonstrate appropriate use of playbooks, automation, AI-assisted analysis, and human validation.
  • Complete scenario-based revision and a timed mock examination containing multiple-choice and performance-based tasks.
  • Assess competencies in Incident Response and Management (24%) and Reporting and Communication (16%) of the CS0-004 exam objectives.

Upon successful completion of this course, learners will be able to:

  • Analyse security telemetry and indicators of malicious activity across endpoint, network, identity, cloud, and hybrid environments.
  • Apply threat intelligence, adversary frameworks, and threat-hunting methods to investigate and prioritise suspicious activity.
  • Conduct vulnerability assessments, interpret findings, prioritise risk, and recommend appropriate remediation or compensating controls.
  • Perform incident-response activities, including triage, scoping, containment, evidence handling, recovery, root-cause analysis, and lessons learned.
  • Use security operations tools, automation, and AI-assisted techniques responsibly to improve detection, investigation, response, and workflow efficiency.
  • Prepare clear technical and executive reports communicating cyber risk, incident impact, remediation priorities, metrics, and escalation requirements.
  • Develop Job-Relevant Analyst Skills: Build practical skills in threat detection, alert triage, vulnerability analysis, incident response, and security reporting.
  • Prepare for an Industry-Recognised Certification: Follow the current CySA+ (CS0-004) domains and prepare for multiple-choice and performance-based exam questions.
  • Progress into Defensive Cybersecurity Roles: Build a portfolio relevant to SOC, cybersecurity, vulnerability, incident response, threat intelligence, and security operations roles.
  • Learn Contemporary Security Operations: Explore cloud and hybrid monitoring, Zero Trust, EDR/XDR, automation, threat intelligence, and responsible AI use.

CompTIA CySA+ (Cybersecurity Analyst)

Course Award

A City College Dublin Professional Diploma Course is a focused, practical programme designed and delivered by an industry practitioner, that consolidates, upskills or reskills learners in a professional area. They are stand-alone qualifications that indicate that you have been trained in a particular area or specific subject matter.

City College Diplomas are suitable for career minded learners wishing to advance their professional skills and prospects. They are widely accepted by employers and many students are sponsored to study here by their organisation.

Corporate Training

Expert Faculty

Learn from the best in your industry

Flexible Learning Options

Study your way, on your time

Career Focused Programmes

Programmes with purpose, aimed at your future

Student Support Services

Here for you, every step of the way

Get in touch

Get in touch

If you have any questions about this course, you can speak directly with a member of our admissions team.

Please get in touch. We’re happy to help.

CompTIA CySA+ (Cybersecurity Analyst)