🔎IT & Cyber Security

CREST CPSA (Prac­ti­tio­ner Security Analyst)

CREST Practitioner Security Analyst — infrastructure and web-application vulnerability assessment practice

200 questions10 topics6 mock papersFree taster

Free 15-question taster · full access with Premium · works on any device

Sample questionLive demo

Tap an answer to try it
✓ 25,000+ exam-style questions✓ Instant explanations✓ Free 15-question taster, no sign-up✓ 149 courses✓ Works offline
Quick answer

Where can I practise for the CREST CPSA exam?

PassNova offers CREST CPSA-aligned practice with a free 15-question taster — 200 multiple-choice questions across the ten syllabus knowledge groups (soft skills and assessment management, core technical skills and cryptography, information gathering and OSINT, networking equipment, Windows and Unix assessment, web technologies, web testing methodologies and techniques, and databases), each with a clear explanation. Unlock the full bank, a study guide and an AI study tutor with PassNova Premium (£4.99/month, 7-day free trial). One honest note: these are original practice questions written from the public CPSA syllabus, not real CREST exam questions, and PassNova is independent of CREST. The real CPSA is a 120-question, 2-hour, closed-book multiple-choice exam at Pearson VUE with a 60% pass mark. Works on any device. Updated for 2026.

Last reviewed

Careers

Jobs and roles this helps you get

CREST's entry-level exam for security testers, covering infrastructure and web vulnerability assessment; a valid CPSA is the prerequisite for the CRT.

Junior penetration tester

Valued by employers

CREST says CPSA demonstrates the knowledge for hands-on pen test roles, and it is the prerequisite for the CRT.

Official source

Security analyst (vulnerability assessment)

Valued by employers

CREST: candidates show they can run basic infrastructure and web application vulnerability scans with common tools and interpret the results.

Official source

Requirements are checked against the National Careers Service, the relevant regulator or the awarding body — follow each source for the current rules.

How it works

How you'll get exam-ready

Why practise here

Built to get you exam-ready

💡

Instant, worked explanations

Every question — right or wrong — comes with a clear explanation, so you learn the why, not just the what.

⏱️

Real, timed mock papers

Sit full-length papers under exam conditions and an indicative pass mark, so the day itself feels familiar.

📊

A live readiness scoreFree + Premium

See how ready you are at a glance — Premium turns it into a predicted result.

🤖

Nova, your AI tutorPremium

Stuck on a question? Nova explains it step by step, in plain English, the moment you ask.

Free vs Premium

Start free. Go Premium when you're serious.

The 15-question taster is always free. Premium unlocks the full bank and the tools that get you over the line.

Free
£0 forever

Everything you need to start revising today.

  • ✓Practise the 15-question taster — no sign-up
  • ✓A worked explanation on every question
  • ✓A basic readiness score
  • ✓Works on any device, even offline
Start practising free →
7-day free trialPremium
£4.99 /month

The full bank, graded papers and Nova — cancel anytime.

  • ✓The full 200-question question bank
  • ✓Nova, the AI tutor, on every question
  • ✓Graded mock & exam papers with a pass verdict
  • ✓Full readiness dashboard + predicted result
  • ✓71 downloadable study-guide PDFs
  • ✓Certificate of completion
Unlock Premium

£4.99/month · 7-day free trial · cancel anytime · secure checkout with Stripe

The complete guide

CREST CPSA explained — Practitioner Security Analyst

CPSA (CREST Practitioner Security Analyst) is CREST's entry-level certification for security testers. It verifies that a candidate can perform a basic infrastructure and web-application vulnerability assessment with common tools and interpret the results, at a level below the CRT and CCT qualifications. A valid CPSA is the prerequisite for the CREST Registered Penetration Tester (CRT).

Format

One written multiple-choice paper of 120 questions in 2 hours (2.5-hour maximum session), sat closed book at a Pearson VUE test centre. One mark per question, no negative marking, and a 60% pass mark (72 of 120). The fee is £275 (exclusive of VAT) and a pass is valid for three years.

The ten knowledge groups (syllabus v2.5)

  • Soft skills & assessment management (A): the engagement lifecycle, UK law (Computer Misuse Act 1990 as amended, Human Rights Act 1998, and current data-protection law), scoping, risk and reporting.
  • Core technical skills (B): IP protocols, network architectures, mapping and tool-output interpretation, OS and application fingerprinting, filtering, file-system permissions and cryptography (encoding vs encryption, DES/3DES/AES/RSA/RC4, MD5/SHA-1, HMAC, and wireless WEP/WPA/WPA2/WPA3).
  • Information gathering & OSINT (C): WHOIS, DNS records and zone transfers, website and search-engine analysis, and information leakage from mail and news headers.
  • Networking equipment (D): management protocols, traffic analysis, ARP/DHCP/CDP/STP/VTP/HSRP, IPsec, VoIP, wireless and Cisco configuration analysis.
  • Windows security assessment (E): domain reconnaissance, user enumeration, Active Directory, password and hash handling, vulnerabilities and patch management.
  • Unix security assessment (F): user enumeration, vulnerabilities, FTP, SMTP, NFS, r-services, X11, RPC and SSH.
  • Web technologies (G), testing methodologies (H) and techniques (I): web protocols, methods, headers and status codes; authentication, authorisation, input validation and session handling; and applied cross-site scripting, SQL injection, traversal and parameter manipulation.
  • Databases (J): Microsoft SQL Server, Oracle and the connection and default-port details web applications rely on.

How to revise

CPSA rewards interpreting tool output — nmap results, traceroute, DNS answers, Cisco snippets, Windows and Unix artefacts and web responses — as much as recalling facts, so practise reading command output and configuration until port numbers, flags, headers and permission bits are second nature. Work through PassNova's topics in study mode, then use timed practice once you can match a finding to its meaning without hesitating.

🔗 The real thing

Free official practice & past papers

Straight from the exam body — official free practice and past papers for CREST CPSA (Practitioner Security Analyst). PassNova's own questions are original exam-style practice; these are the awarding body's materials.

External official sites — free where shown; some may require a free account. Links open in a new tab.

Take the real test

Where the real exam comes from

PassNova is free practice — you sit the official CREST CPSA (Practitioner Security Analyst) with the body that runs it.

ℹ️ PassNova is an independent study resource and is not affiliated with, authorised by or endorsed by CREST. These are original practice questions written from the publicly available CPSA syllabus and general security references, not real CREST examination questions.

External official sites — fees and booking are handled by the provider, not PassNova.

FAQ

CREST CPSA (Practitioner Security Analyst): your questions answered

CPSA is a single written multiple-choice paper of 120 questions sat over 2 hours, with a 2.5-hour maximum session at a Pearson VUE test centre. It is closed book — no notes, internet or devices are allowed. Each question is worth one mark with no negative marking, and the pass mark is 60% (72 of 120 marks).

Pass your CREST CPSA — first time.

Start with a free 15-question taster, then unlock the full bank, Nova and a study guide with Premium.

Try the free taster →Premium £4.99/mo · 7-day free trial📘 Study guide