CREST Study Guide 2026

Everything you need to pass the CREST exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

📋 CREST Exam Format at a Glance

120
Questions
120 min
Time Limit
60.00%
Passing Score

📚 CREST Topics to Study (52)

✍️ Sample CREST Questions & Answers

1. When prioritizing vulnerabilities, which combination of factors from CVSS and business context is MOST appropriate?
CVSS base score plus asset criticality and exploitability in the wild

Effective prioritization combines the CVSS base score with environmental factors such as asset business value and evidence of active exploitation to focus remediation effort.

2. What is a key element of effective vulnerability management?
Continuous monitoring and patching

A key element of effective vulnerability management is continuous monitoring and patching. Security threats and vulnerabilities constantly evolve, so ongoing surveillance of systems and networks is necessary to detect new weaknesses. Regularly applying security patches and updates ensures that known flaws are addressed promptly, significantly reducing the attack surface.

3. An analyst is reviewing a PCAP and notices beaconing traffic on port 443 to an external IP with jitter of ±10%. What does the jitter most likely indicate?
C2 framework using sleep with jitter to evade detection

Modern C2 frameworks deliberately introduce jitter (random variance in beacon intervals) to avoid pattern-based network detection.

4. What does the OWASP ASVS (Application Security Verification Standard) provide?
A framework of security requirements for designing, developing, and testing secure web applications

OWASP ASVS defines three levels of security verification requirements that organizations can use as a baseline for application security testing and development standards.

5. What is a security baseline in the context of architecture design?
A defined minimum set of security configurations that all systems must meet

A security baseline specifies the minimum security configuration standards required for systems, ensuring consistent protection across an environment.

6. What does a DMZ (Demilitarized Zone) in network architecture provide?
A segmented network zone for publicly accessible services, isolated from the internal network

A DMZ places externally facing services between two firewalls, limiting the damage if a public-facing server is compromised.

🎯 Free CREST Practice Tests

📖 CREST Guides & Articles

Your CREST Study Path
1. Learn with Flashcards → 2. Drill Practice Tests → 3. Take the Full Exam Simulation
Was this helpful?