Soft Skills & Assessment Management
18 practice questions with explanations — 15 free to try
2 of these 18 questions are in the free 15-question taster · the full topic is part of Premium
PassNova has 18 CREST CPSA (Practitioner Security Analyst) practice questions on Soft Skills & Assessment Management, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Soft Skills & Assessment Management: example questions & answers
2 worked examples with answers and explanations below. Try 15 CREST CPSA (Practitioner Security Analyst) questions free in the browser; the full 18-question Soft Skills & Assessment Management bank is part of PassNova Premium.
A client asks why they should commission a penetration test rather than rely only on an automated vulnerability scan. Which statement best captures the additional value a penetration test provides?
- AIt confirms the network will stay free of vulnerabilities for the next year once the issues listed in the report are fixed
- BIt discharges the client's legal duty to protect personal data because an expert has reviewed it
- CIt removes the need for routine patching because the tester secures each host during the work
- DIt validates findings by safely exploiting them and chaining weaknesses together to show real business impact✓
Answer: A penetration test adds value over a raw scan by verifying which findings are genuinely exploitable, chaining several weaknesses together and demonstrating the actual business impact, which reduces false positives and helps prioritise remediation. It cannot guarantee a network is vulnerability-free, does not patch systems, and never transfers or discharges the client's own legal obligations.
During scoping, a client states that the testing team will be given no prior knowledge of the internal network, no credentials and no documentation, and must work purely from an external position. Which testing format does this describe?
- AGrey box testing
- BCompliance auditing
- CWhite box testing
- DBlack box testing✓
Answer: Black box testing gives the tester little or no prior information, simulating an external attacker who must discover the environment. White box testing supplies full internal detail such as architecture, credentials or source code, and grey box testing shares only partial knowledge. Compliance auditing measures controls against a defined standard rather than attempting to compromise the environment.