The CySA+ study guide carrying 267 ratings and a 4.7 average is written for a version that stops being offered in English in December. The Sybex guide for the version you will actually sit has three ratings.
That gap is the whole problem with shopping for CompTIA CySA+ books right now. CompTIA launched CySA+ V4 on 23 June 2026 under the code CS0-004, and the previous version, CS0-003, keeps running in English until 22 December 2026. Both exams are live. Both have books on sale. The cheap, well-reviewed, heavily recommended ones are for the version that is being switched off, and Amazon’s sort order does nothing to warn you. This guide covers the CS0-004 study guide, its companion question bank, four analyst books that cover ground a 560-page exam guide has no room for, and the CS0-003 titles you should recognize on sight.
Verified August 2026 against CompTIA’s exam pages, the published CS0-003 objectives, publisher tables of contents, and live Amazon US listings.
Which CySA+ exam you are buying a book for
Check the exam code on the cover before anything else. CS0-004 is the current version. CS0-003 is the one being retired.
| Exam | Status | Key dates |
|---|---|---|
| CS0-004 (CySA+ V4) | Current | Launched 23 June 2026 |
| CS0-003 (CySA+ V3) | Retiring | English exam retires 22 December 2026; Japanese, Portuguese and Spanish versions retire 23 March 2027 |
Both routes award the identical certification, valid for three years from the day you pass. So sitting CS0-003 is not cheating, and the credential is not worth less. The question is purely whether you can be ready in time. As of 31 August 2026 that leaves 113 days, a little over 16 weeks, and testing centre availability in December is not something to gamble on.
The honest default: if you have not already started, study for CS0-004. If you are mid-way through a CS0-003 book and can realistically test by early December, finish what you started. Do not buy a CS0-003 book today intending to start from scratch.
What changed between CS0-003 and CS0-004
The structure did not move. Both versions run a maximum of 85 questions in 165 minutes, mixing multiple choice with performance-based questions, and both pass at 750 on a 100 to 900 scale. For CS0-004 CompTIA recommends roughly four years as a SOC or vulnerability analyst, where the older version framed it as incident response or SOC analyst experience, though nothing stops you sitting either earlier.
What moved is the weighting. CompTIA’s V4 exam page lists four domains by name, without numbering them, and the percentages shifted in both directions:
| Domain | CS0-003 | CS0-004 | Change |
|---|---|---|---|
| Security Operations | 33% | 34% | +1 |
| Vulnerability Management | 30% | 26% | -4 |
| Incident Response and Management | 20% | 24% | +4 |
| Reporting and Communication | 17% | 16% | -1 |
Incident response gained the most and vulnerability management lost the most, a straight four point swap between the two. The reweighting is not the whole change. CS0-004 introduces dedicated coverage of artificial intelligence in security operations, and it widens cloud-native and hybrid environments, automation, and zero trust past what the older version asked for. Those last three are not new arrivals. CompTIA’s published CS0-003 objectives already name zero trust, hybrid and serverless deployments, containerization, and security orchestration, automation and response, so a CS0-003 book does cover them, just in the thinner form the older exam required. Artificial intelligence is the real addition. CompTIA’s own version comparison calls AI coverage limited in the older version and dedicated in this one, and the published CS0-003 objectives never name it at all. That is the substantive reason to buy current, and it matters more than the code printed on the cover.
The six CySA+ books at a glance
Two of these target CS0-004 directly. The other four are working analyst books chosen for the practitioner depth a 560-page exam guide has no room for, and none of them carries an exam code, so they stay useful after you certify. Selection came from CompTIA’s published exam pages for CS0-004 and live Amazon US listings checked in a New York session; nothing here was lab tested, because these are books, and the honest claim is verification rather than benchmarking.
| Book | Publisher | Published | Pages | Price | Rating |
|---|---|---|---|---|---|
| CompTIA CySA+ Study Guide, 4th ed | Sybex | Aug 2026 | 560 | $54.60 | 3.3 (3) |
| CompTIA CySA+ Practice Tests, 4th ed | Sybex | Aug 2026 | 432 | $45.00 | no ratings yet |
| Practical Threat Detection Engineering | Packt | Jul 2023 | 328 | $28.19 | 4.7 (50) |
| Practical Vulnerability Management | No Starch | Sep 2020 | 192 | $29.95 | 4.5 (74) |
| Applied Incident Response | Wiley | Jan 2020 | 464 | $26.07 | 4.7 (224) |
| The Practice of Network Security Monitoring | No Starch | Jul 2013 | 376 | $45.58 | 4.6 (185) |
One thing to understand before you spend anything. Reporting and Communication is 16% of CS0-004 and it is the domain that gets shortchanged, and the Sybex study guide is where you can measure it. Count the pages in that book’s own table of contents and the split is stark: Security Operations runs to 220 pages, Vulnerability Management 146, Incident Response and Management 94, and Reporting and Communication 32. That last domain carries nearly half the exam weight of Security Operations and gets under a sixth of its pages, which works out at about two pages per point of weighting against six and a half.
Among the analyst books, Practical Vulnerability Management goes furthest on that ground, giving reporting three chapters including one on generating asset and vulnerability reports, though it frames all of it around vulnerability data rather than incidents. None of the analyst books is written to an exam blueprint, so whatever the study guide gives you there is what you get in the shape CS0-004 tests it. Budget your own time for that domain rather than expecting a book to carry you through it.
1. CompTIA CySA+ Study Guide, Fourth Edition
Mike Chapple and David Seidl wrote this one, the pair behind Sybex’s Security+ and CySA+ guides. It is the study guide Sybex built for CS0-004, and it is where most candidates will start.
Sybex put the paperback out on 3 August 2026, 41 days after CS0-004 went live, but the Kindle edition landed on 26 June, three days after launch. The wait was for print, not for the book. The reviews have not caught up either way: the 3.3 average, shared across both formats, comes from exactly three ratings. Three ratings decide nothing. Treat that number as noise until the count climbs, and do not read the 4.7 on the older edition as evidence this one is worse.
560 pages, and the print includes a year of access to Sybex’s online test bank, flashcards and glossary once you activate it. That online component is a real part of what you are paying for, and the activation code is single use, so a second-hand copy will most likely arrive with that access already claimed. Buy new.
Who it is for: anyone sitting CS0-004, which should be most people reading this. Skip it if you are finishing a CS0-003 attempt before December, or if you want a second opinion in print before committing at this price. In print it is the most expensive book here at around $54.60, about $18 above the outgoing edition. That price dropped ten dollars in a single day while this guide was being written, so check it before you order.
2. CompTIA CySA+ Practice Tests, Fourth Edition
Same authors, same exam code, a different job. This is 1,000 questions with worked explanations, organized against the CS0-004 objectives, plus a year of online test-bank access.
It arrived on 18 August 2026, later than the study guide, and carries no ratings at all yet. Question banks earn their place by surfacing the objectives you skimmed. Working through a thousand questions and reading the explanations for the ones you miss is a better use of a week than a second pass through the textbook.
Sybex also sells a Certification Kit bundling this with the study guide, listed at $95 when checked against $99.60 for the two bought separately. That is under five dollars saved, and the gap moves with the study guide’s price, so check both before deciding.
Who it is for: anyone who has finished a study guide and wants to find their weak domains before paying the CySA+ exam fee. Skip it if you have not read the material yet, since practice questions taken cold teach very little, or if the test bank included with the study guide covers your needs.
3. Practical Threat Detection Engineering
Security Operations is the largest domain on CS0-004 at 34%, and the study guide spends more pages on it than on anything else, so breadth is not the gap. What a study guide cannot do is teach you to build a detection. That is what Megan Roddie, Jason Deyalsingh and Gary Katz wrote.

The subject is how detections get built, tested and validated rather than how a particular console is driven. It walks through developing a detection, validating it against real adversary behavior, and measuring whether it actually fires, which is the daily reality behind the alert triage material on CS0-004. Pair it with a running log pipeline and it stops being theory. If you do not have one, our guides on installing Wazuh on Ubuntu and setting up Graylog for log analysis both give you somewhere to send events and something to write rules against.
328 pages, published July 2023, and holding 4.7 from 50 ratings.
Who it is for: analysts who can read an alert but have never written one, and anyone whose Security Operations practice scores are the weakest. Skip it if you already work in detection engineering, because much of it will be familiar, or if you need exam-shaped questions rather than working practice.
4. Practical Vulnerability Management
Andrew Magnusson’s book is the shortest here by a wide margin at 192 pages, and that is the point. It covers what to do with scanner output rather than how to run a scanner.
Vulnerability Management dropped from 30% to 26% in CS0-004, which still leaves it the second largest domain. CS0-004 frames it as risk-based prioritization, and that is exactly where this book lives: building an asset inventory, deciding what a score actually means in your environment, and getting findings remediated rather than merely reported. Running Greenbone in a container while you read it gives you real output to prioritise instead of the book’s examples.
Published September 2020 by No Starch, 4.5 from 74 ratings.
Who it is for: anyone who has produced a scan report and had no idea which twenty findings to chase first. Skip it if you want tool-specific depth on Nessus or Qualys, since it is deliberately vendor-neutral. Note also that a 2020 book predates the software bill of materials and exploit-prediction scoring that CS0-004 now expects, so you will need the study guide for those.
5. Applied Incident Response
Incident Response and Management gained four points in CS0-004, the largest increase of any domain. Steve Anson’s book is the cheapest pick here and the most reviewed of the six.
464 pages covering the mechanics: scoping an incident, remote triage across a network, memory and disk analysis, log review, and the containment decisions that have to be made while the intrusion is still live. It leans on free tooling throughout, so you can follow along without a license budget. The attack frameworks CS0-004 names, and the response phases it tests, are the spine of this book rather than an appendix.
Wiley published it in January 2020 and it holds 4.7 from 224 ratings, at around $26.07. Over six and a half years old, and the tooling chapters show it in places, but incident response methodology has aged far better than any specific console.
Who it is for: anyone who would freeze if handed a suspected compromise on a Friday afternoon. Skip it if you need incident response in cloud-native environments, which CS0-004 leans on harder than its predecessor did and which this book predates.
6. The Practice of Network Security Monitoring
Richard Bejtlich’s book is the oldest thing on this list and needs the most honest framing, so here it is up front: it was published in July 2013, which makes it just over 13 years old, and it costs more than every other analyst book here.
Its tooling chapters describe 2013 software. They predate Bro being renamed Zeek and describe a Security Onion that no longer resembles the current release. If you buy it expecting a working install guide you will be annoyed within a chapter.
What survives is the reasoning. The book’s argument, that prevention eventually fails and the job is therefore detection and response built on collected evidence, is the assumption the CySA+ syllabus rests on. Bejtlich is precise about what data to collect, why full packet capture and session data answer different questions, and how an analyst should actually work a case. That framing has not aged. For current tooling to sit alongside it, our Suricata install guide and the Nmap scanning guide are closer to what you will actually run, and network security concepts explained covers the underlying threat and defence vocabulary.
Who it is for: readers who want the methodology behind monitoring rather than a tool manual, and who can mentally substitute current software names. Skip it if your budget is tight, because at around $45.58 it is poor value next to Applied Incident Response at roughly $26, or if a 2013 print will frustrate you.
The CS0-003 books still on the shelf
These are the books you will meet first if you search by name and sort by price or reviews. All three were buyable when this was checked, and all three target CS0-003, which closes in English on 22 December 2026. They are listed so you can recognize them, and they are deliberately not linked.
| Book | Publisher | Published | Price | Rating |
|---|---|---|---|---|
| CompTIA CySA+ Study Guide, 3rd ed (CS0-003) | Sybex | Jul 2023 | $36.12 | 4.7 (267) |
| CompTIA CySA+ Practice Tests, 3rd ed (CS0-003) | Sybex | Aug 2023 | $28.65 | 4.5 (61) |
| CySA+ All-in-One Exam Guide, 3rd ed (CS0-003) | McGraw Hill | Nov 2023 | $41.06 | 4.3 (27) |
The pricing tells the story on its own. The outgoing Sybex study guide is $36.12 against $54.60 for the current one, so for anyone starting from scratch today the wrong book is also the cheaper book, by $18.48, and it carries 267 ratings against three. The two things a casual shopper sorts by, price and rating count, both point at the edition that expires.
Two further notes. McGraw Hill has not shipped an All-in-One for CS0-004, so its CySA+ line is still on the retiring code, and its stock was down to the last couple of copies when checked. CompTIA’s own Official Self-Paced Study Guide for CS0-003 showed as unavailable entirely. If you are buying for an exam that is still current elsewhere in the CompTIA stack, our guides to CompTIA Security+ books, Network+ study guides and Linux+ books apply the same exam-code check, and the wider cybersecurity and penetration testing reading list covers ground beyond any single certification.
What 16 weeks to the cutoff actually buys you
If the retiring exam still tempts you because the books are cheaper, do the arithmetic before you decide rather than after.
From 31 August 2026 to 22 December 2026 is 113 days. Call it 16 weeks. Out of that, budget two weeks at the end for booking, travel and the possibility that your preferred testing centre has no December slots, because everyone else chasing the deadline is competing for the same seats. Remote proctoring through OnVUE takes most of that risk away if you are set up for it, so the buffer matters most if you plan to sit in a test centre. That leaves about 14 weeks of actual study.
Fourteen weeks is comfortable for someone already working in a SOC who is mostly filling gaps. It is tight for a career changer starting from a fresh Security+ pass, and it is not enough for someone who has never worked an alert. Miss the date and you start again on the current version: the CS0-003 book becomes background reading and you buy the CS0-004 one anyway.
Your voucher may well survive the switch, but check rather than assume. CompTIA’s help centre says a standard voucher is tied to the exam rather than to a particular version, so it can usually be redeemed against CS0-004. The binding voucher terms are more guarded: they state that vouchers are exam series specific and in some cases exam code specific, that special retake vouchers cannot be redeemed for other versions of the same exam, that once an exam retires its vouchers are no longer valid, and that no voucher purchase is refundable. If you already hold one, read the code printed on it before you plan around it. What you lose by overrunning is narrower than it sounds. The structure did not move, so most of a CS0-003 preparation still applies. What does not carry over is the AI material and the expanded treatment of software bills of materials, exploit prediction and zero trust, plus the price of buying the right book afterwards.
That is the real wager, and it is about time rather than money. Buy for CS0-004 and the extra $18.48 over the outgoing guide is simply the cost of studying for the version that still exists. If that gap decides it for you, the Kindle edition is $39.00, which undercuts the current paperback by more than fifteen dollars and lands within about three dollars of the outgoing one. Budget another $45 if you want the practice tests.




