Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

README.md

CREST CPSA Certification Study Guide

🎓 A comprehensive, exam-aligned study guide for CREST CPSA certification candidates

License: MIT CPSA Aligned Last Updated


📚 About This Guide

This repository contains a professional-grade, comprehensive study guide for the CREST Practitioner Security Analyst (CPSA) certification. Designed by a PhD researcher in cybersecurity at Newcastle University, this guide bridges the gap between academic knowledge and practical penetration testing frameworks.

🎯 What This Is

  • Exam-Aligned: Covers CPSA Syllabus v2.5 in detail
  • Comprehensive: 10+ chapters covering all major skills
  • Practical: Real-world examples from UK financial services and healthcare contexts
  • Professional: Written by active cybersecurity researchers
  • Open Source: Free for educational use (MIT License)
  • Community-Driven: Feedback and contributions welcome

🚀 What This Isn't

  • ❌ Not a replacement for official CREST materials
  • ❌ Not a guarantee of exam pass (but significantly improves preparation)
  • ❌ Not an official CREST publication
  • ❌ Not a substitute for hands-on penetration testing experience

📖 Contents

Chapter 1: Engagement Lifecycle & Penetration Testing Frameworks ✅ COMPLETE

Skills Covered: A1 (Engagement Lifecycle), A3 (Scoping)
Exam Coverage: 20-25%
Time to Complete: 2-3 hours
Status: ✅ Publication-Ready

What You'll Learn:

  • What penetration testing is and why organizations need it
  • Business value and technical value of PT assessments
  • The CREST three-phase penetration testing programme (Preparation, Testing, Follow-Up)
  • Detailed breakdown of all preparation steps (A1-A7)
  • Detailed breakdown of all testing steps (B1-B9)
  • Detailed breakdown of all follow-up steps (C1-C6)
  • Scoping fundamentals and best practices
  • Three testing styles: Black Box, Grey Box, White Box
  • Common mistakes to avoid
  • Legal compliance requirements

Exam Preparation Resources Included:

  • 5 CPSA exam tips (strategically placed)
  • 10 practice exam questions (multiple choice format)
  • Complete answer key with detailed rationales
  • 5 common mistakes sections with solutions
  • Legal compliance checklist (20 actionable items)
  • Quick reference tables and summaries

Chapter 2: Law, Compliance & Legal Framework 🔄 IN PROGRESS

Skills Covered: B1, B2, D1, D2
Exam Coverage: 15-20%
Estimated Completion: End of November 2025

Topics to Cover:

  • Computer Misuse Act 1990 (UK)
  • GDPR and Data Protection Act 2018
  • PCI-DSS requirements for payment card security
  • ISO 27001 information security standards
  • NIS Regulations (Critical Infrastructure)
  • HIPAA (Healthcare Data)
  • Regulation of Investigatory Powers Act 2000 (RIPA)
  • Rules of Engagement (RoE) legal requirements
  • Contract law and liability
  • Insurance and professional responsibility
  • Incident response obligations

Chapter 3: Reporting & Documentation 📅 PLANNED

Skills Covered: C1, C2, C3, C4
Exam Coverage: 10-15%
Planned Release: December 2025


Chapter 4: Testing Techniques & Methodologies 📅 PLANNED

Skills Covered: B3, B4, B5, B6, B7, B8
Exam Coverage: 25-30%
Planned Release: January 2026


🎓 Who This Is For

Audience Time Use Case
CPSA Candidates 2-3 hours/chapter Comprehensive exam preparation
Security Professionals 1-2 hours/chapter PT framework reference
Managers/CISOs 1-1.5 hours/chapter PT program planning and ROI
Executives 45-60 min/chapter High-level security understanding
Students 2-3 hours/chapter Career entry into cybersecurity
Career Changers 3-4 hours/chapter Comprehensive introduction

🚀 Getting Started

Option 1: Read on GitHub (Easiest)

  1. Click on Chapter-01.md
  2. Read directly in browser
  3. Use GitHub's search feature to find topics
  4. Star the repository if helpful!

Option 2: Clone Repository (For Offline Study)

git clone https://github.com/yourusername/CPSA-Study-Guide.git
cd CPSA-Study-Guide