Login to profile

CREST Practitioner Security Analyst

Book now with Pearson Vue

The CREST Practitioner Security Analyst (CPSA) examination is an entry-level examination that tests a candidate’s knowledge in assessing operating systems and common network services at a basic level below that of the main CRT and CCT qualifications.  The CPSA examination also includes an intermediate level of web application security testing and methods to identify common web application security vulnerabilities.
The examination covers a common set of core skills and knowledge.   The candidate must demonstrate that they have the knowledge to perform basic infrastructure and web application vulnerability scan using commonly available tools and interpret the results to locate security vulnerabilities.

Success will confer CREST Practitioner Security Analyst status to the individual.


Examination Format
The examination is a multiple choice written assessment and is a pre-requisite for sitting the CREST Registered Penetration Tester examination.

You can download the following documents from the links below:

Syllabus for the CPSA examination
Notes for Candidates to aid examination preparation


For costs and availability please refer to individual country booking.  The examination is delivered at Pearson Vue test centres.


Recommended Preparation Material
The CREST Assessors panel regularly identifies common themes and consolidates common questions and answers from candidates and from the industry in relation to the CREST certification examinations. Candidates are advised to familiarise themselves with these, although they are free to disregard them if they wish. The latest information can be accessed on our FAQS page.

The following material and media has been cited as helpful preparation for this examination by previous candidates:

Reading Material:
Network Security Assessment (by O’Reilly, 2nd edition)
Hacking Exposed Linux
Red Team Field Manual (RTFM) (by Ben Clarke)
Nmap Network Scanning: The Official Nmap Project (by Gordon Lyon)
Guide to Network Discovery and Security Scanning
Grey Hat Hacking (by Allen Harper, Shon Harris & Jonathan Ness)


Cyberskills Training – CREST Approved Training Provider
ICSI – CREST Approved Training Provider
PGI Cyber Academy – CREST Approved Training Provider
QA – CREST Approved Training Provider
Telefonica Cybersecurity & Cloud Tech SL – CREST Approved Training Provider


Useful Information for Candidates
Details of the Logistics and Timings of CREST examinations can be found in the Examination Preparation pages for your country of choice
CREST’s Policy for Candidates requiring special arrangements including additional time to accommodate a medical condition (including examinations delivered via Pearson Vue)
Terms and Conditions for CREST Examinations (includes hard disk drive wiping policy)