🎓 A comprehensive, exam-aligned study guide for CREST CPSA certification candidates
This repository contains a professional-grade, comprehensive study guide for the CREST Practitioner Security Analyst (CPSA) certification. Designed by a PhD researcher in cybersecurity at Newcastle University, this guide bridges the gap between academic knowledge and practical penetration testing frameworks.
- ✅ Exam-Aligned: Covers CPSA Syllabus v2.5 in detail
- ✅ Comprehensive: 10+ chapters covering all major skills
- ✅ Practical: Real-world examples from UK financial services and healthcare contexts
- ✅ Professional: Written by active cybersecurity researchers
- ✅ Open Source: Free for educational use (MIT License)
- ✅ Community-Driven: Feedback and contributions welcome
- ❌ Not a replacement for official CREST materials
- ❌ Not a guarantee of exam pass (but significantly improves preparation)
- ❌ Not an official CREST publication
- ❌ Not a substitute for hands-on penetration testing experience
Skills Covered: A1 (Engagement Lifecycle), A3 (Scoping)
Exam Coverage: 20-25%
Time to Complete: 2-3 hours
Status: ✅ Publication-Ready
- What penetration testing is and why organizations need it
- Business value and technical value of PT assessments
- The CREST three-phase penetration testing programme (Preparation, Testing, Follow-Up)
- Detailed breakdown of all preparation steps (A1-A7)
- Detailed breakdown of all testing steps (B1-B9)
- Detailed breakdown of all follow-up steps (C1-C6)
- Scoping fundamentals and best practices
- Three testing styles: Black Box, Grey Box, White Box
- Common mistakes to avoid
- Legal compliance requirements
- 5 CPSA exam tips (strategically placed)
- 10 practice exam questions (multiple choice format)
- Complete answer key with detailed rationales
- 5 common mistakes sections with solutions
- Legal compliance checklist (20 actionable items)
- Quick reference tables and summaries
Skills Covered: B1, B2, D1, D2
Exam Coverage: 15-20%
Estimated Completion: End of November 2025
- Computer Misuse Act 1990 (UK)
- GDPR and Data Protection Act 2018
- PCI-DSS requirements for payment card security
- ISO 27001 information security standards
- NIS Regulations (Critical Infrastructure)
- HIPAA (Healthcare Data)
- Regulation of Investigatory Powers Act 2000 (RIPA)
- Rules of Engagement (RoE) legal requirements
- Contract law and liability
- Insurance and professional responsibility
- Incident response obligations
Skills Covered: C1, C2, C3, C4
Exam Coverage: 10-15%
Planned Release: December 2025
Skills Covered: B3, B4, B5, B6, B7, B8
Exam Coverage: 25-30%
Planned Release: January 2026
| Audience | Time | Use Case |
|---|---|---|
| CPSA Candidates | 2-3 hours/chapter | Comprehensive exam preparation |
| Security Professionals | 1-2 hours/chapter | PT framework reference |
| Managers/CISOs | 1-1.5 hours/chapter | PT program planning and ROI |
| Executives | 45-60 min/chapter | High-level security understanding |
| Students | 2-3 hours/chapter | Career entry into cybersecurity |
| Career Changers | 3-4 hours/chapter | Comprehensive introduction |
- Click on
Chapter-01.md - Read directly in browser
- Use GitHub's search feature to find topics
- Star the repository if helpful!
git clone https://github.com/yourusername/CPSA-Study-Guide.git
cd CPSA-Study-Guide