CREST CPSA (Practitioner Security Analyst)
CREST Practitioner Security Analyst — infrastructure and web-application vulnerability assessment practice
Jump into a topic All 10 topics ↓
- Core Technical Skills34 questions
- Windows Security Assessment24 questions
- Networking Equipment22 questions
- Unix Security Assessment22 questions
- Soft Skills & Assessment Management18 questions
- Information Gathering & OSINT18 questions
- Web Technologies16 questions
- Web Testing Methodologies16 questions
- Web Testing Techniques16 questions
- Databases14 questions
Free 15-question taster · full access with Premium · works on any device
Where can I practise for the CREST CPSA exam?
PassNova offers CREST CPSA-aligned practice with a free 15-question taster — 200 multiple-choice questions across the ten syllabus knowledge groups (soft skills and assessment management, core technical skills and cryptography, information gathering and OSINT, networking equipment, Windows and Unix assessment, web technologies, web testing methodologies and techniques, and databases), each with a clear explanation. Unlock the full bank, a study guide and an AI study tutor with PassNova Premium (£4.99/month, 7-day free trial). One honest note: these are original practice questions written from the public CPSA syllabus, not real CREST exam questions, and PassNova is independent of CREST. The real CPSA is a 120-question, 2-hour, closed-book multiple-choice exam at Pearson VUE with a 60% pass mark. Works on any device. Updated for 2026.
Last reviewed
A complete map of the CREST CPSA syllabus
Tap a topic to start practising it — every question comes with a clear explanation. Or work the whole bank in study mode.
- Core Technical Skills34 questions
- Windows Security Assessment24 questions
- Networking Equipment22 questions
- Unix Security Assessment22 questions
- Soft Skills & Assessment Management18 questions
- Information Gathering & OSINT18 questions
- Web Technologies16 questions
- Web Testing Methodologies16 questions
- Web Testing Techniques16 questions
- Databases14 questions
Jobs and roles this helps you get
CREST's entry-level exam for security testers, covering infrastructure and web vulnerability assessment; a valid CPSA is the prerequisite for the CRT.
Junior penetration tester
Valued by employersCREST says CPSA demonstrates the knowledge for hands-on pen test roles, and it is the prerequisite for the CRT.
Official sourceSecurity analyst (vulnerability assessment)
Valued by employersCREST: candidates show they can run basic infrastructure and web application vulnerability scans with common tools and interpret the results.
Official sourceRequirements are checked against the National Careers Service, the relevant regulator or the awarding body — follow each source for the current rules.
How you'll get exam-ready
Built to get you exam-ready
Instant, worked explanations
Every question — right or wrong — comes with a clear explanation, so you learn the why, not just the what.
Real, timed mock papers
Sit full-length papers under exam conditions and an indicative pass mark, so the day itself feels familiar.
A live readiness scoreFree + Premium
See how ready you are at a glance — Premium turns it into a predicted result.
Nova, your AI tutorPremium
Stuck on a question? Nova explains it step by step, in plain English, the moment you ask.
Start free. Go Premium when you're serious.
The 15-question taster is always free. Premium unlocks the full bank and the tools that get you over the line.
Everything you need to start revising today.
- ✓Practise the 15-question taster — no sign-up
- ✓A worked explanation on every question
- ✓A basic readiness score
- ✓Works on any device, even offline
The full bank, graded papers and Nova — cancel anytime.
- ✓The full 200-question question bank
- ✓Nova, the AI tutor, on every question
- ✓Graded mock & exam papers with a pass verdict
- ✓Full readiness dashboard + predicted result
- ✓71 downloadable study-guide PDFs
- ✓Certificate of completion
£4.99/month · 7-day free trial · cancel anytime · secure checkout with Stripe
CREST CPSA explained — Practitioner Security Analyst
CPSA (CREST Practitioner Security Analyst) is CREST's entry-level certification for security testers. It verifies that a candidate can perform a basic infrastructure and web-application vulnerability assessment with common tools and interpret the results, at a level below the CRT and CCT qualifications. A valid CPSA is the prerequisite for the CREST Registered Penetration Tester (CRT).
Format
One written multiple-choice paper of 120 questions in 2 hours (2.5-hour maximum session), sat closed book at a Pearson VUE test centre. One mark per question, no negative marking, and a 60% pass mark (72 of 120). The fee is £275 (exclusive of VAT) and a pass is valid for three years.
The ten knowledge groups (syllabus v2.5)
- Soft skills & assessment management (A): the engagement lifecycle, UK law (Computer Misuse Act 1990 as amended, Human Rights Act 1998, and current data-protection law), scoping, risk and reporting.
- Core technical skills (B): IP protocols, network architectures, mapping and tool-output interpretation, OS and application fingerprinting, filtering, file-system permissions and cryptography (encoding vs encryption, DES/3DES/AES/RSA/RC4, MD5/SHA-1, HMAC, and wireless WEP/WPA/WPA2/WPA3).
- Information gathering & OSINT (C): WHOIS, DNS records and zone transfers, website and search-engine analysis, and information leakage from mail and news headers.
- Networking equipment (D): management protocols, traffic analysis, ARP/DHCP/CDP/STP/VTP/HSRP, IPsec, VoIP, wireless and Cisco configuration analysis.
- Windows security assessment (E): domain reconnaissance, user enumeration, Active Directory, password and hash handling, vulnerabilities and patch management.
- Unix security assessment (F): user enumeration, vulnerabilities, FTP, SMTP, NFS, r-services, X11, RPC and SSH.
- Web technologies (G), testing methodologies (H) and techniques (I): web protocols, methods, headers and status codes; authentication, authorisation, input validation and session handling; and applied cross-site scripting, SQL injection, traversal and parameter manipulation.
- Databases (J): Microsoft SQL Server, Oracle and the connection and default-port details web applications rely on.
How to revise
CPSA rewards interpreting tool output — nmap results, traceroute, DNS answers, Cisco snippets, Windows and Unix artefacts and web responses — as much as recalling facts, so practise reading command output and configuration until port numbers, flags, headers and permission bits are second nature. Work through PassNova's topics in study mode, then use timed practice once you can match a finding to its meaning without hesitating.
Free official practice & past papers
Straight from the exam body — official free practice and past papers for CREST CPSA (Practitioner Security Analyst). PassNova's own questions are original exam-style practice; these are the awarding body's materials.
External official sites — free where shown; some may require a free account. Links open in a new tab.
Where the real exam comes from
PassNova is free practice — you sit the official CREST CPSA (Practitioner Security Analyst) with the body that runs it.
ℹ️ PassNova is an independent study resource and is not affiliated with, authorised by or endorsed by CREST. These are original practice questions written from the publicly available CPSA syllabus and general security references, not real CREST examination questions.
External official sites — fees and booking are handled by the provider, not PassNova.
CREST CPSA (Practitioner Security Analyst): your questions answered
CPSA is a single written multiple-choice paper of 120 questions sat over 2 hours, with a 2.5-hour maximum session at a Pearson VUE test centre. It is closed book — no notes, internet or devices are allowed. Each question is worth one mark with no negative marking, and the pass mark is 60% (72 of 120 marks).
CPSA costs £275 (exclusive of VAT), booked through Pearson VUE. A pass is valid for three years from the date you sit the exam. CREST publishes current pricing and booking details on crest-approved.org, so check there before you book.
CPSA has no prerequisites and is CREST's entry-level qualification, testing knowledge of assessing operating systems, common network services and web applications. A valid CPSA is itself the prerequisite for the CREST Registered Penetration Tester (CRT) examination.
It follows the CREST CPSA Technical Syllabus v2.5 (December 2023), the current published version. The ten topics map onto the syllabus's ten appendices (A to J). Where the syllabus still lists older material — for example the Data Protection Act 1998 — PassNova teaches the current position (the Data Protection Act 2018 and UK GDPR) and notes the change in the explanation.
No — these are original practice questions written from the public syllabus, not CREST's confidential exam content, and PassNova is not affiliated with CREST. The first 15 questions are free with no sign-up; the full 200-question bank, a study guide and the Nova AI tutor unlock with PassNova Premium (£4.99/month or £39.99/year, with a 7-day free trial).
CREST's entry-level exam for security testers, covering infrastructure and web vulnerability assessment; a valid CPSA is the prerequisite for the CRT. Junior penetration tester: CREST says CPSA demonstrates the knowledge for hands-on pen test roles, and it is the prerequisite for the CRT. Security analyst (vulnerability assessment): CREST: candidates show they can run basic infrastructure and web application vulnerability scans with common tools and interpret the results.
You can practise a free 15-question taster with no sign-up. To unlock the full 200-question bank, an AI study tutor and a downloadable study guide, upgrade to PassNova Premium — £4.99/month with a 7-day free trial.
Premium unlocks every Premium course in full, plus Nova (the AI study tutor), smart spaced-repetition practice, a study planner, mock pass certificates and downloadable PDF study guides — for £4.99/month or £39.99/year. Cancel anytime.
PassNova has 200 exam-style CREST CPSA (Practitioner Security Analyst) questions and 6 timed mock tests, each with a clear explanation. A free 15-question taster is spread across the topics; the rest unlock with Premium.
CPSA (CREST Practitioner Security Analyst) is CREST's entry-level infrastructure and web-application security-testing certification and the prerequisite for the CREST Registered Penetration Tester (CRT). Verified against crest-approved.org and Pearson VUE's CREST page in September 2026: the exam is 120 multiple-choice questions in 2 hours (with a 2.5-hour maximum session at Pearson VUE), sat closed book, and the pass mark is 60% — that is 72 of 120 marks, one mark per question with no negative marking. It is delivered at Pearson VUE test centres, costs £275 (exclusive of VAT), and a CPSA pass is valid for three years. The current syllabus is the CPSA Technical Syllabus v2.5 (December 2023), whose ten appendices (A to J) are the ten topics used here. Because CPSA is assessed entirely by multiple choice, this bank can mirror its question format closely; what it cannot reproduce is CREST's confidential exam content or the closed-book test-centre conditions. PassNova's questions are original, written from the public syllabus and general security references (RFCs, vendor documentation, NIST, OWASP and legislation.gov.uk); current UK law is taught where the syllabus still names the repealed Data Protection Act 1998, which was replaced in 2018 by the Data Protection Act 2018 and the UK GDPR. PassNova is independent of, and not endorsed by, CREST.
No — deliberately. Every PassNova question is written from the published exam objectives, not copied from a live exam. Sites that republish real questions ("exam dumps") breach the candidate agreement you accept when you book, and using them can void your result or cost you a credential you already hold. PassNova matches the real exam's style, difficulty and domain weighting without reproducing its content.
Pass your CREST CPSA — first time.
Start with a free 15-question taster, then unlock the full bank, Nova and a study guide with Premium.