What problem does it solve? Preparing for the CompTIA CySA+ (CS0-004) certification requires mastering four large domains of security analyst knowledge, and candidates often lack a structured, exam-weighted reference covering logging, threat hunting, vulnerability prioritization, incident response, and reporting. ## Core Features & Use Cases - Domain-Structured References: Detailed guides for all four exam domains — Security Operations (34%), Vulnerability Management (26%), Incident Response (24%), and Reporting & Communication (16%). - Tools & Frameworks Mapping: 15 tool categories (SIEM, EDR, scanners, SOAR) and 12 frameworks (MITRE ATT&CK, Kill Chain, NIST, CIS) mapped to exam domains. - Exam Strategy Guidance: PBQ and multiple-choice strategies, time management, and common gotchas like CVSS vs EPSS prioritization and TLP misuse. - Use Case: A SOC analyst preparing for CySA+ asks how to prioritize vulnerabilities; the skill explains combining CVSS v3.1 base scores with EPSS probability and business context, citing the Domain 2 reference. ## Quick Start Ask the agent to explain CySA+ Domain 3 incident response phases and evidence handling using the comptia-cysa skill.