Choose your language
CompTIA Security+ & CySA+ Practice Course
Over 400,000 professionals on the platform
Exclusive for businesses

CompTIA Security+ & CySA+ Practice Course

Prepare for both CompTIA Security+ and CySA+ with a comprehensive practice course built around real exam objectives. Master threat detection, incident response, network security, and vulnerability management through scenario-driven content. Sharpen your analyst skills and walk into exam day with the confidence to pass.

Dedika for students

What your team will master:

  • Apply the MITRE ATT&CK framework to map adversary tactics and close detection gaps.

  • Analyse network traffic, packet captures, and log sources to uncover malicious activity.

  • Configure and evaluate firewalls, IDS, IPS, and zero-trust network segmentation controls.

  • Understand PKI, cryptographic algorithms, and access control models tested on both exams.

  • Conduct threat hunting using hypothesis-driven methodology with SIEM and EDR tooling.

  • Interpret practice exam results to target weak domains and maximise certification scores.

How your team learns in practice CompTIA Security+ & CySA+ Practice Course

How your team practises CompTIA Security+ & CySA+ Practice Course

Professionals from these companies study at Dedika

ActemiumFR
Nunner LogisticsNL
GT Constructora GeotécnicaCR
Sydel StarBR
Metrô de São PauloBR
Aguas AndinasCL
DSMIN
MeridianbetRS
CDHCN

Course content

8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Cybersecurity Fundamentals and Exam Overview

  • Lesson 1 • Security Frameworks and Compliance Concepts

    Introduces widely adopted security frameworks and compliance-driven control selection. Students connect regulatory concepts to practical security programme design.

  • Lesson 2 • Security+ and CySA+ Exam Blueprints

    Maps exam domains, objective weights, and question formats for both certifications. Provides a study roadmap aligned to CompTIA's published objectives.

  • Lesson 3 • Threat Actors and Attack Motivations

    Classifies adversary types by capability, intent, and sponsorship. Understanding attacker motivation informs defensive prioritisation throughout the course.

  • Lesson 4 • Core Security Concepts and Terminology

    Defines confidentiality, integrity, availability, authentication, and authorisation. These terms underpin every subsequent technical topic across both exams.

Chapter 2See details

Network Security Architecture and Protocols

  • Lesson 1 • VPN, Remote Access, and Secure Tunneling

    Explains IPsec, SSL/TLS VPN, split tunnelling, and SD-WAN security. Remote access security is a high-frequency topic on both certification exams.

  • Lesson 2 • Wireless Security Standards and Attacks

    Reviews WPA2, WPA3, EAP variants, and common wireless attack techniques. Wireless vulnerabilities appear consistently across Security+ exam objectives.

  • Lesson 3 • Core Network Protocols and Vulnerabilities

    Examines TCP/IP, DNS, DHCP, HTTP/S, and their known attack surfaces. Protocol-level knowledge is tested heavily on Security+ performance-based questions.

  • Lesson 4 • Firewalls, IDS, and IPS Technologies

    Differentiates stateful, next-generation, and web application firewalls alongside IDS and IPS deployment modes. Students match technology to threat scenario.

  • Lesson 5 • Network Segmentation and Secure Design

    Covers VLANs, DMZs, zero-trust architecture, and microsegmentation. Segmentation limits lateral movement, a concept central to both exam domains.

Chapter 3See details

Identity, Access Management, and Cryptography

  • Lesson 1 • Cryptographic Algorithms and Key Management

    Differentiates symmetric, asymmetric, and hashing algorithms by use case and strength. Key management lifecycle directly impacts encryption effectiveness.

  • Lesson 2 • Access Control Models and Privilege Management

    Compares DAC, MAC, RBAC, and ABAC models and applies least-privilege principles. Privilege mismanagement is a leading cause of breaches examined in CySA+ scenarios.

  • Lesson 3 • Authentication Protocols and MFA

    Examines password-based, token-based, biometric, and certificate-based authentication. Multi-factor authentication is a core control tested on both exams.

  • Lesson 4 • Directory Services and Federation

    Covers LDAP, Active Directory, SAML, OAuth 2.0, and OpenID Connect. Federation enables cross-domain identity trust, a scenario-heavy topic on CySA+.

  • Lesson 5 • Public Key Infrastructure and Certificate Management

    Explains CA hierarchy, certificate lifecycle, CRL, and OCSP. PKI underpins TLS, code signing, and email encryption tested across both exams.

Chapter 4See details

Threats, Attacks, and Vulnerability Types

  • Lesson 1 • Malware Classification and Behaviour Analysis

    Distinguishes viruses, worms, ransomware, rootkits, and fileless malware by propagation and payload. Behavioural indicators are central to CySA+ threat analysis.

  • Lesson 2 • Application and Web-Based Attacks

    Analyses SQL injection, XSS, CSRF, buffer overflow, and API abuse. Application-layer attacks dominate CySA+ analyst scenario questions.

  • Lesson 3 • Vulnerability Scanning and Risk Prioritisation

    Introduces CVSS scoring, vulnerability scanner output interpretation, and remediation prioritisation. Vulnerability management is a primary CySA+ competency domain.

  • Lesson 4 • Network-Based and Denial-of-Service Attacks

    Examines DDoS amplification, man-in-the-middle, ARP poisoning, and session hijacking. Network attack recognition is tested in both exam performance-based items.

  • Lesson 5 • Social Engineering and Phishing Techniques

    Covers phishing, spear phishing, vishing, smishing, and pretexting attack vectors. Human-layer attacks are consistently represented in Security+ scenario questions.

Chapter 5See details

Security Operations and Monitoring

  • Lesson 1 • Log Sources and Data Collection

    Identifies critical log sources including endpoints, firewalls, DNS, and authentication systems. Comprehensive log collection is the foundation of effective detection.

  • Lesson 2 • Endpoint Detection and Response

    Covers EDR telemetry, process behaviour monitoring, and host-based IOC detection. Endpoint visibility closes gaps that network monitoring alone cannot address.

  • Lesson 3 • SIEM Architecture and Use Case Development

    Explains SIEM data normalisation, correlation rules, and dashboard design. Use case development translates threat intelligence into actionable detection logic.

  • Lesson 4 • Network Traffic Analysis and Packet Inspection

    Applies packet capture tools and flow data to identify anomalous behaviour. Traffic analysis skills are directly assessed in CySA+ performance-based questions.

  • Lesson 5 • Alert Triage and Escalation Procedures

    Establishes a structured triage methodology for classifying, prioritising, and escalating security alerts. Effective triage reduces mean time to respond across SOC operations.

Chapter 6See details

Incident Response and Digital Forensics

  • Lesson 1 • Containment, Eradication, and Recovery

    Details short-term and long-term containment strategies, root cause removal, and system restoration. These phases directly limit attacker dwell time and data loss.

  • Lesson 2 • Incident Response Lifecycle and Planning

    Maps the six-phase IR lifecycle from preparation through lessons learned. A documented IR plan reduces response time and limits breach impact.

  • Lesson 3 • Digital Forensics Principles and Evidence Handling

    Establishes chain of custody, order of volatility, and forensic imaging standards. Proper evidence handling ensures admissibility and investigation integrity.

  • Lesson 4 • Post-Incident Analysis and Reporting

    Structures lessons-learned reviews, root cause analysis, and executive reporting. Post-incident documentation drives control improvements and satisfies audit requirements.

  • Lesson 5 • Memory and Disk Forensics Techniques

    Applies memory acquisition and disk artifact analysis to uncover attacker activity. These techniques surface indicators missed by network-only monitoring.

Chapter 7See details

Threat Intelligence and Threat Hunting

  • Lesson 1 • Threat Intelligence Fundamentals

    Defines strategic, operational, tactical, and technical intelligence and their consumers. Intelligence type determines how analysts apply it to detection and response.

  • Lesson 2 • Threat Hunting Methodology

    Introduces hypothesis-driven hunting, data source selection, and hunt documentation. Proactive hunting surfaces threats that evade automated detection systems.

  • Lesson 3 • Indicator Management and Enrichment

    Covers IOC ingestion, enrichment with open-source intelligence, and indicator lifecycle management. Enriched indicators improve detection fidelity and reduce false positives.

  • Lesson 4 • Intelligence-Driven Detection Engineering

    Translates threat intelligence into SIEM rules, EDR policies, and network signatures. Detection engineering operationalises intelligence into measurable security outcomes.

  • Lesson 5 • MITRE ATT&CK Framework Application

    Maps adversary tactics, techniques, and procedures to ATT&CK matrix entries. Framework-based analysis structures detection coverage and gap identification.

Chapter 8See details

Security Assessment, Governance, and Exam Readiness

  • Lesson 1 • Full-Length Practice Exam Simulation

    Delivers timed, full-length practice exams mirroring Security+ and CySA+ question distributions. Simulated testing conditions build exam stamina and time management skills.

  • Lesson 2 • Data Security and Privacy Controls

    Addresses data classification, DLP technologies, data retention, and privacy-by-design principles. Data protection controls appear across both exam domains.

  • Lesson 3 • Penetration Testing Concepts and Phases

    Distinguishes reconnaissance, scanning, exploitation, and reporting phases of a penetration test. Pen test concepts appear in both Security+ and CySA+ exam objectives.

  • Lesson 4 • Security Programme Governance and Risk Management

    Covers risk assessment methodologies, security policy hierarchy, and business impact analysis. Governance knowledge is tested in Security+ policy and risk domain questions.

  • Lesson 5 • Targeted Review and Weak Area Remediation

    Uses practice exam results to identify knowledge gaps and assigns focused remediation content. Targeted review maximises score improvement in the final preparation phase.

Certification

Your valid completion certificate

This course is for you:

  • IT support technician: ready to move into a dedicated security role.

  • Recent computer science graduate: pursuing first cybersecurity certification credentials.

  • Network administrator: wanting formal validation of existing security knowledge.

  • Career changer from finance or healthcare: drawn to cybersecurity's growing job market.

  • Junior SOC analyst: aiming to formalise skills and earn analyst-level certifications.

  • Military veteran transitioning: using discipline and technical training to move into cybersecurity.

Related courses

FAQ

Who is Dedika?

Is the certificate valid in the United Kingdom?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course