Free CREST CPSA Exam Prep
CREST Practitioner Security Analyst (CPSA)
Prepare for the CREST CPSA exam without spending hundreds on expensive prep courses. Free study guides, practice questions, flashcards, and related exam resources.
Quick Facts
Explore More CREST Penetration Testing Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
CREST CREST Penetration Testing Certifications License: Complete Roadmap
Follow this path to organize your licensing and exam preparation
Phase 1: Core Technical FoundationsYou are here
Master TCP/IP, IPv4/IPv6, port numbers, ICMP, and network architecture basics.
Phase 2: Cryptography and Protocols
Drill symmetric/asymmetric algorithms, hash functions, SSL/TLS, IPsec, and SSH.
Phase 3: Network Mapping and Vulnerability ID
Practice Nmap flags, service enumeration, OSINT/WHOIS/DNS, and vulnerability assessment.
Phase 4: OS Assessment and Web Testing
Cover Windows/Unix enumeration, Active Directory, OWASP Top 10, and database security.
Phase 5: Full Simulations and Soft Skills
Simulate timed 120-Q exams, review legal frameworks, scoping, and report writing.
Can You Take the CREST CPSA Exam?
Check if you meet the basic eligibility requirements
- •Exam taken at a Pearson VUE test centre; online proctoring not available
- •Closed-book exam — no notes or electronic devices permitted
- •No negative marking; each correct answer scores 1 mark
CREST CPSA Quick Facts
Time to Get Licensed
6-10 weeks for most candidates with prior networking knowledge
From start to license in hand
Retake Policy
Candidates must wait before retaking; refer to CREST's official exam policy for current waiting periods.
Total Cost Breakdown
Free CREST CPSA Prep Tools
Reported exam pass rate: CREST does not publish an official pass rate for the CPSA exam.. These figures describe exam candidates, not OpenExamPrep user outcomes. Check the exam sponsor’s website for published statistics.
100 Practice Questions
CPSA-focused questions covering all official syllabus domains from protocols to web testing.
AI-Powered Learning
Get targeted explanations for every question and prioritised study recommendations.
2026 Updated
Review the CREST CPSA Technical Syllabus V2.5 and current exam format.
Free Access
Practice CPSA-style questions free with full explanations and wrong-answer guidance.
What You'll Study
12 chapters covering the exam topics in this guide
Chapter 1: Soft Skills, Legal Framework & Assessment Management
4 sections
Chapter 2: Core Networking: IP Protocols & Network Architectures
5 sections
Chapter 3: Cryptography & Secure Communication Protocols
3 sections
Chapter 4: Background Information Gathering & OSINT Reconnaissance
4 sections
Chapter 5: Networking Equipment & Infrastructure Protocols
5 sections
Chapter 6: Network Mapping, Nmap Techniques & Target Identification
6 sections
Chapter 7: Vulnerability Identification & Tool Output Analysis
4 sections
Chapter 8: Microsoft Windows Security Assessment & Active Directory
6 sections
Chapter 9: Unix & Linux Security Assessment & Legacy Services
6 sections
Chapter 10: Web Architectures, Technologies & Testing Methodologies
6 sections
Chapter 11: Web Testing Techniques & OWASP Top Vulnerabilities
7 sections
Chapter 12: Database Security Assessment & SQL Injection
4 sections
CREST CPSA Exam Details
CREST Practitioner Security Analyst (CPSA)
Administered by CREST
Exam Content Breakdown
Based on the official CREST content outline
Engagement lifecycle, scoping, legal framework (Computer Misuse Act, Data Protection Act), risk, and professional reporting.
IPv4/IPv6, TCP/UDP/ICMP, network architectures, OS fingerprinting, port scanning, file-system permissions, and audit techniques.
Symmetric/asymmetric algorithms (AES, 3DES, RSA, RC4), hash functions (MD5, SHA-1), HMAC, SSL/TLS, IPsec, SSH, and PGP.
WHOIS, DNS record types and zone transfers, Google hacking, OSINT, and mail-header analysis.
SNMP, DHCP, NTP, ARP, CDP, STP, VTP, HSRP, VRRP, TACACS+, IPsec, SIP/VoIP, and 802.11 wireless protocols.
Nmap scan types and flags, service enumeration, banner grabbing, OS detection, and network topology analysis.
Identifying known vulnerabilities in services, CVE referencing, patch-level assessment, and risk-based prioritisation.
Domain reconnaissance, user and group enumeration, Active Directory basics, Windows password attacks, patch management, and Exchange.
User enumeration, FTP, SMTP/Sendmail, NFS, R-services, X11, RPC, SSH, and common Unix/Linux vulnerabilities.
OWASP Top 10 (SQLi, XSS, CSRF, directory traversal), session attacks, fuzzing, common database ports, enumeration, and stored procedures.
What's Included
12 Chapters
Complete exam coverage
Practice Quizzes
With detailed explanations
Free to Start
No credit card required

Quality Exam Prep Shouldn't Cost Hundreds
I'm Ran Chen, an engineer with 20+ years of coding experience. I passed my Life Insurance license, EA exam, SIE, Series 6, 63, 65, and finally the CFP® exam.
Through all these exams, one thing became clear: exam prep is expensive. But with AI, we can change that. Quality preparation can now be free for everyone.
What's Next After the CREST CPSA?
After passing the CREST CPSA, you can pursue these career paths
CREST CPSA Exam FAQ
Official CREST Resources
Verify information with these official sources
More Free Resources
Ready to Start Your Free CREST CPSA Prep?
Review the study guide, practice key concepts, and use the free tools at your own pace.
