CREST - Practitioner Security Analyst (CPSA)



Only 4 Days



Classroom / Online / Hybrid

Next date

Next date:

15/3/2022 (Tuesday)


On this accelerated 4-day CREST Practitioner Security Analyst course, you'll gain the core knowledge and skills needed to assess operating systems and common network services - 20% faster than traditional training.

The CPSA is the first certification in CREST's Penetration Testing career pathway, and through it, you'll be immersed in the fundamentals of penetration testing.

Your expert instructor will teach you to locate security vulnerabilities by performing basic infrastructure and web application testing and interpreting the results.

On this CREST CPSA course you'll cover a range of exciting topics including:

  • Core Technical Skills - OS fingerprinting, cryptography and network mapping
  • Information Gathering & Open Source - Google Hacking and DNS checks
  • Networking Equipment - configuration analysis and networking protocols
  • Windows and Unix Security Assessments - common vulnerabilities and patch management
  • Web Testing Techniques - fuzzing, CRLF and Session ID attacks

You'll be immersed in the curriculum with our unique Lecture | Lab | Review technique, accelerating your learning and equipping you with hands-on experience. You'll also benefit from 24/7 lab access and get access to CREST-accredited courseware.

This accelerated CPSA training prepares you for the CREST Practitioner Security Analyst exam. Don't pass the first time? Don't worry - you'll be covered by our Certification Guarantee.

This course is ideal for you if you're a systems administrator, incident handler or IT manager wishing to expand your knowledge on Pen testing and Digital Forensics.

Firebrand's corporate training processes, policies and procedures have been successfully assessed against the CREST criteria for the Approved Training Provider discipline. Firebrand are currently working to get course content recognised.

Seven reasons why you should sit your course with Firebrand Training

  1. Two options of training. Choose between residential classroom-based, or online courses
  2. You'll be certified in just 4 days. With us, you’ll be trained in record time
  3. Our course is all-inclusive. A one-off fee covers all course materials, exams, accommodation and meals. No hidden extras
  4. Pass first time or train again for free. This is our guarantee. We’re confident you’ll pass your course first time. But if not, come back within a year and only pay for accommodation, exams and incidental costs
  5. You’ll learn more. A day with a traditional training provider generally runs from 9am – 5pm, with a nice long break for lunch. With Firebrand Training you’ll get at least 12 hours/day quality learning time, with your instructor
  6. You’ll learn faster. Chances are, you’ll have a different learning style to those around you. We combine visual, auditory and tactile styles to deliver the material in a way that ensures you will learn faster and more easily
  7. You’ll be studying with the best. We’ve been named in Training Industry’s “Top 20 IT Training Companies of the Year” every year since 2010. As well as winning many more awards, we’ve trained and certified 111,358 professionals, and we’re partners with all of the big names in the business


Benefits of Training with Firebrand

  • Two options of training - Residential classroom-based, or online courses
  • A purpose-built training centre – get access to dedicated Pearson VUE Select facilities.
  • Certification Guarantee – pass first time or train again free (just pay for accommodation, exams and incidental costs)
  • Everything you need to certify – you’ll sit your exam at the earliest available opportunity after the course - either immediately after your classroom course, or as soon as there are slots available, if you've taken it online
  • No hidden extras – one cost covers everything you need to certify


Firebrand follows the CREST CPSA Technical Syllabus

Syllabus Knowledge Group A: Soft Skills and Assessment Management

  • Module 1: Engagement Lifecycle
  • Module 2: Law & Compliance
  • Module 3: Scoping
  • Module 4: Understanding Explaining and Managing Risk
  • Module 5: Record Keeping, Interim Reporting & Final Results

Syllabus Knowledge Group B: Core Technical Skills

  • Module 1: IP Protocols
  • Module 2: Network Architectures
  • Module 3: Network Mapping & Target Identification
  • Module 4: Interpreting Tool Output
  • Module 5: B5 Interpreting Tool Output
  • Module 6: OS Fingerprinting
  • Module 7: Application Fingerprinting and Evaluating Unknown Services
  • Module 8: Network Access Control Analysis
  • Module 9: Cryptography 
  • Module 10: Applications of Cryptography
  • Module 11: File System Permissions
  • Module 12: Audit Techniques

Syllabus Knowledge Group C: Background Information Gathering and Open Source

  • Module 1: Registration Records
  • Module 2: Domain Name Server (DNS)
  • Module 3: Customer Web Site Analysis
  • Module 4: Google Hacking and Web Enumeration
  • Module 5: NNTP Newsgroups and Mailing Lists
  • Module 6: Information Leakage from Mail & News Headers

Syllabus Knowledge Group D: Networking Equipment

  • Module 1: Management Protocols
  • Module 2: Network Traffic Analysis
  • Module 3: Networking Protocols
  • Module 4: IPSec
  • Module 5: VoIP
  • Module 6: Wireless 
  • Module 7: Configuration Analysis

Syllabus Knowledge Group E: Microsoft Windows Security Assessment

  • Module 1: Domain Reconnaissance
  • Module 2: User Enumeration
  • Module 3: Active Directory
  • Module 4: Windows Passwords
  • Module 5: Windows Vulnerabilities
  • Module 6: Windows Patch Management Strategies
  • Module 7: Desktop Lockdown
  • Module 8:  Exchange
  • Module 9: Common Windows Applications

Syllabus Knowledge Group F: Unix Security Assessment

  • Module 1: User enumeration
  • Module 2: Unix vulnerabilities
  • Module 3: FTP 
  • Module 4: Sendmail / SMTP
  • Module 5: Network File System (NFS)
  • Module 6: R* services 
  • Module 7: X11
  • Module 8: RPC services
  • Module 9: SSH

Syllabus Knowledge Group G: Web Technologies

  • Module 1: Web Server Operation
  • Module 2: Web Servers & their Flaws
  • Module 3: Web Enterprise Architectures
  • Module 4: Web Protocols
  • Module 5: Web Mark-up Languages
  • Module 6: Web Programming Languages
  • Module 7: Web Application Servers
  • Module 8: Web APIs
  • Module 9: Web SubComponents

Syllabus Knowledge Group H: Web Testing Methodologies

  • Module 1: Web Application Reconnaissance
  • Module 2: Threat Modelling and Attack Vectors
  • Module 3: Information Gathering from Web Mark-up
  • Module 4: Authentication Mechanisms
  • Module 5: Authorisation Mechanisms
  • Module 6: Input Validation
  • Module 7: Information Disclosure in Error Messages
  • Module 8: Use of Cross Site Scripting Attacks
  • Module 9: Use of Injection Attacks
  • Module 10: Session Handling
  • Module 11: Encryption
  • Module 12: Source Code Review

Syllabus Knowledge Group I: Web Testing Techniques - only applicable to CRT

Syllabus Knowledge Group J: Databases

  • Module 1: Microsoft SQL Server
  • Module 2: Oracle RDBMS
  • Module 3: Web / App / Database Connectivity

Exam Track

As part of your accelerated course, you'll sit the following exam at the Firebrand Training centre, covered by your Certification Guarantee:

CREST Practitioner Security Analyst CPSA

  • Format: Multiple choice; closed book
  • Duration: 2 hours
  • Passing score: 60%
  • Number of questions: 120

The CREST Practitioner Security Analyst certification is valid for 3 years.

To achieve CREST Registered Status, you must pass both the Crest Practitioner Security Analyst (CPSA) and CREST Registered Tester (CRT) exams.

What's Included

Your accelerated course includes:

  • Accommodation *
  • Meals, unlimited snacks, beverages, tea and coffee *
  • On-site exams **
  • Exam vouchers **
  • Practice tests **
  • Certification Guarantee ***
  • Courseware
  • Up-to 12 hours of instructor-led training each day
  • 24-hour lab access
  • Digital courseware **
  • * For residential training only. Doesn't apply for online courses
  • ** Some exceptions apply. Please refer to the Exam Track or speak with our experts
  • *** Pass first time or train again free (just pay for accommodation, exams and incidental costs)


To attend this course, you should have a good understanding of the technical aspects of IT with at least one year's experience in network or server administration.

Unsure whether you meet the prerequisites? Don’t worry. Your training consultant will discuss your background with you to understand if this course is right for you.


Here's the Firebrand Training review section. Since 2001 we've trained exactly 111,358 students and asked them all to review our Accelerated Learning. Currently, 96.66% have said Firebrand exceeded their expectations.

Read reviews from recent accelerated courses below or visit Firebrand Stories for written and video interviews from our alumni.

"Fantastic instructor. Professional, enthusiastic, and knows the subject inside out. An absolute pleasure to learn from. "
J.M.J., Program Planning Professionals Ltd. (8/10/2018 (Monday) to 11/10/2018 (Thursday))

"The instructor we had was very knowledgeable and approachable and willing to delve further into detail (time permitting). Course content was very informative and additional reading material is very helpful so I know where to concentrate my efforts."
Philip Freeman, Xpertex. (8/10/2018 (Monday) to 11/10/2018 (Thursday))

"Excellent training - trainers and venue ideally setup to support your learning needs."
Chris Cobb, Xpertex ltd. (8/10/2018 (Monday) to 11/10/2018 (Thursday))

"Brilliant course which was very comprehensive. Long hours but instructor was also flexible and happy to adapt pace to needs of group/individual. "
J.T.. (20/8/2018 (Monday) to 23/8/2018 (Thursday))

"Excellent facilities and training structure. Long hours but worth investing the time."
William Davies. (20/8/2018 (Monday) to 23/8/2018 (Thursday))

Course Dates

CREST - Practitioner Security Analyst (CPSA)




Book now

15/11/2021 (Monday)

18/11/2021 (Thursday)

Finished - Leave feedback


15/3/2022 (Tuesday)

18/3/2022 (Friday)


Book now

Latest Reviews from our students