CompTIA has updated the CompTIA Cybersecurity Analyst (CySA+) certification with CySA+ V4, refreshing the exam objectives to better reflect current security operations work. The new version emphasizes threat detection, vulnerability management, incident response, and clear communication of security risks across network, endpoint, cloud, and hybrid environments.
For candidates planning their certification path, the transition from CySA+ V3 to V4 is an important change. The core purpose of CySA+ remains the same - validating cybersecurity analyst skills - but the domain weighting and practical emphasis have shifted.

| Exam Domain | CySA+ V3 | CySA+ V4 |
| Security Operations | 33% | 34% |
| Vulnerability Management | 30% | 26% |
| Incident Response and Management | 20% | 24% |
| Reporting and Communication | 17% | 16% |
The most noticeable change is the increased weighting for incident response and management. V4 also maintains security operations as the largest domain while placing vulnerability management in a more risk-based context.
Security Operations accounts for 34% of the V4 exam. Candidates are expected to identify and investigate suspicious activity across networks, endpoints, cloud environments, and hybrid infrastructure.
The V4 objectives include modern analysis and monitoring tools such as security information and event management (SIEM), endpoint detection and response (EDR), extended detection and response (XDR), packet analysis tools, threat-intelligence platforms, and user and entity behavior analytics.
Incident Response and Management has increased from 20% in V3 to 24% in V4. Candidates should understand the complete incident response process, including preparation, detection, analysis, containment, eradication, recovery, and post-incident activities.
The updated objectives also cover practical response tasks such as triage, evidence gathering, escalation, remediation, restoration, root cause analysis, and corrective-action development.
Vulnerability Management represents 26% of V4, compared with 30% in V3. The reduced percentage does not make the topic less important. Instead, V4 emphasizes how analysts prioritize and mitigate vulnerabilities using factors such as exploitability, active exploitation intelligence, asset value, impact, remediation availability, and validation of remediation.
Candidates should be prepared to evaluate risk in context rather than treat every vulnerability finding in the same way.
CySA+ V4 reflects the environments security analysts work in today. The objectives include cloud infrastructure assessment tools, cloud and hybrid security operations, automation and orchestration, and AI-related security operations concepts.
For example, V4 includes AI risks such as hallucinations, data exposure, model poisoning, and malicious prompts, along with possible uses of AI for log analysis, incident investigation, event correlation, and automation.
Reporting and Communication represents 16% of the V4 exam. Cybersecurity analysts need to communicate findings to both technical and business stakeholders. Candidates should understand vulnerability reports, risk scorecards, action plans, incident declarations, executive summaries, post-incident reporting, and relevant metrics and KPIs.
This domain reinforces that effective security work depends on clear decisions and communication, not only technical investigation.
Candidates who are still preparing for the previous version should plan around the published retirement schedule:
●CySA+ V3 English exam: retires December 22, 2026.
●CySA+ V3 Japanese, Portuguese, and Spanish versions: retire March 23, 2027.
Candidates should confirm current availability and registration details with CompTIA before scheduling, particularly as the retirement dates approach.
Candidates who have already made significant progress with V3 materials and can test before the applicable retirement date may decide to complete V3. Those starting their preparation now may prefer V4 because its objectives better reflect current security operations practices and newer tools.
CySA+ V4 is especially relevant for professionals pursuing or developing skills for roles such as:
●Security Analyst
●SOC Analyst
●Vulnerability Analyst
●Incident Response Specialist
●Cybersecurity Operations Professional
The appropriate choice depends on your readiness, schedule, and the version available in your preferred language.
As CySA+ evolves, candidates should make sure their preparation reflects the current objectives. CertQueen CySA+ V4 practice questions and exam preparation materials can help candidates review security operations, vulnerability management, incident response, and reporting topics through exam-focused scenarios.
Use practice questions to identify weaker domains, review the reasoning behind each answer, and return to the official objectives for areas that need more study. Combining updated materials with practical experience in monitoring, analysis, and incident response can help candidates prepare with greater confidence.
CySA+ V4 retains the cybersecurity analyst foundation of V3 while shifting more attention toward practical security operations, incident response, risk-based vulnerability management, and modern cloud and hybrid environments. Understanding these changes helps candidates choose a preparation path that matches both their timeline and their career goals.