CREST CPSA EXAM PRACTICE 2026
UPDATE QUESTIONS AND CORRECT
VERIFIED ANSWERS ALREADY GRADED
A+ (BRAND NEW VISION)
NTLMv2 - ANS-NTLMv2 was developed in response to attacks against the LM
authentication protocol. It uses the MD5 password hash algorithm.
NTLM Hash - ANS-Successor to the LM hash. A more advanced hash used to
store Windows passwords, based off the RC4 algorithm.
OSPF (Open Shortest Path First) - ANS-A link-state routing protocol used on IP
networks.
Static Routing - ANS-A type of routing used by a network administrator to
manually specify the mappings in the routing table.
Dynamic Routing - ANS-Allows a router to determine the best route between two
nodes automatically and then store this information in a routing table.
Port 1 - ANS-TCP Port Service Multiplexer (TCPMUX)
Port 5 - ANS-Remote Job Entry (RJE)
Port 7 - ANS-ECHO or ICMP
Port 18 - ANS-MSG ICP
Port 29 - ANS-time
Port 37 - ANS-Host Name Server (Nameserv)
Port 43 - ANS-WHOIS
Port 42 - ANS-Gopher Services
Port 70 - ANS-Gopher Services
Port 118 - ANS-SQL Services
,Port 119 - ANS-NNTP (Network News Transfer Protocol)
Port 79 - ANS-finger
Port 159 - ANS-SQL Server
Port 103 - ANS-X.400 Standard
Port 190 - ANS-Gateway Access Control Protocol (GACP)
Port 197 - ANS-Directory Location Service (DLS)
Port 396 - ANS-Novell Netware over IP
Port 444 - ANS-Simple Network Paging Protocol (SNPP)
Port 458 - ANS-Apple QuickTime
Computer Misuse Act 1990 - ANS-An Act which makes illegal a number of activities
such as deliberately planting viruses, hacking, using ICT equipment for fraud.
Human Rights Act 1998 - ANS-Act of Parliament that incorporated the European
Convention on Human Rights into UK law, making it enforceable in UK courts.
Data Protection Act 1998 - ANS-The UK law that tells organisations how they must
protect the personal data of real people. (NOW GDPR)
GDPR (General Data Protection Regulation) - ANS-New European Union law on data
protection and privacy for individuals.
XSS (Cross Site Scripting) - ANS-A type of application attack where the attacker
takes advantage of scripting and input validation vulnerabilities in an interactive
website to attack legitimate users.
MySQL < 5.1 Authentication Bypass - ANS-Bug that allows authentication even
when password provided is incorrect.
DoS - ANS-Denial of Service
DDoS (Distributed Denial of Service) - ANS-An attack on a computer or network
device in which multiple computers send data and requests to the device in an
attempt to overwhelm it so that it cannot perform normal operations.
Passive OS fingerprinting - ANS-Observing host behavior and packets (DHCP, TCP,
etc) to determine OS
, Active OS Fingerprinting - ANS-Sends specially crafted packets to the remote OS
and analyzes the received response.
AES (Advanced Encryption Standard) - ANS-A block cipher created in the late 1990s
that uses a 128-bit block size and a 128-, 192-, or 256-bit key size. Practically
uncrackable.
TKIP (Temporal Key Integrity Protocol) - ANS-A security protocol created by the
IEEE 802.11i task group to replace WEP.
SMTP User Enumeration - ANS-EXPN VRFY
Sendmail < 8.12.9 Buffer Overflow - ANS-The prescan function in Sendmail 8.12.9
allows remote attackers to execute arbitrary code via buffer overflow attacks.
RPC (Remote Procedure Call) Enumeration - ANS-Can be assessed using
portmapper requests.
Non-Persistent XSS - ANS-XSS that occurs when the attacker's script that is
injected is not stored in the backend.
Persistent XSS - ANS-Malicious code that remains on a website until it is removed.
SOAP - ANS-Simple Object Access Protocol
Simple Object Access Protocol (SOAP) - ANS-An XML-based communication
protocol used for sending messages between applications via the Internet.
XML injection - ANS-An attack that injects XML tags and data into a database.
XXE (XML External Entity) Attack - ANS-This attack occurs when XML input
containing a reference to an external entity is processed by a weakly configured
XML parser.
Denial of Service (DoS) - ANS-An attack that disrupts the normal functioning of a
targeted server, service, or network by overwhelming it with a flood of traffic.
Buffer overflow attacks - ANS-Exploits that involve writing more data to a buffer
than it can hold, potentially allowing attackers to execute arbitrary code.
Attacks on vulnerable scripts - ANS-Exploits that target weaknesses in web scripts
to gain unauthorized access or cause harm.
URL manipulation - ANS-The process of altering a URL to gain unauthorized
access or extract sensitive information.
UPDATE QUESTIONS AND CORRECT
VERIFIED ANSWERS ALREADY GRADED
A+ (BRAND NEW VISION)
NTLMv2 - ANS-NTLMv2 was developed in response to attacks against the LM
authentication protocol. It uses the MD5 password hash algorithm.
NTLM Hash - ANS-Successor to the LM hash. A more advanced hash used to
store Windows passwords, based off the RC4 algorithm.
OSPF (Open Shortest Path First) - ANS-A link-state routing protocol used on IP
networks.
Static Routing - ANS-A type of routing used by a network administrator to
manually specify the mappings in the routing table.
Dynamic Routing - ANS-Allows a router to determine the best route between two
nodes automatically and then store this information in a routing table.
Port 1 - ANS-TCP Port Service Multiplexer (TCPMUX)
Port 5 - ANS-Remote Job Entry (RJE)
Port 7 - ANS-ECHO or ICMP
Port 18 - ANS-MSG ICP
Port 29 - ANS-time
Port 37 - ANS-Host Name Server (Nameserv)
Port 43 - ANS-WHOIS
Port 42 - ANS-Gopher Services
Port 70 - ANS-Gopher Services
Port 118 - ANS-SQL Services
,Port 119 - ANS-NNTP (Network News Transfer Protocol)
Port 79 - ANS-finger
Port 159 - ANS-SQL Server
Port 103 - ANS-X.400 Standard
Port 190 - ANS-Gateway Access Control Protocol (GACP)
Port 197 - ANS-Directory Location Service (DLS)
Port 396 - ANS-Novell Netware over IP
Port 444 - ANS-Simple Network Paging Protocol (SNPP)
Port 458 - ANS-Apple QuickTime
Computer Misuse Act 1990 - ANS-An Act which makes illegal a number of activities
such as deliberately planting viruses, hacking, using ICT equipment for fraud.
Human Rights Act 1998 - ANS-Act of Parliament that incorporated the European
Convention on Human Rights into UK law, making it enforceable in UK courts.
Data Protection Act 1998 - ANS-The UK law that tells organisations how they must
protect the personal data of real people. (NOW GDPR)
GDPR (General Data Protection Regulation) - ANS-New European Union law on data
protection and privacy for individuals.
XSS (Cross Site Scripting) - ANS-A type of application attack where the attacker
takes advantage of scripting and input validation vulnerabilities in an interactive
website to attack legitimate users.
MySQL < 5.1 Authentication Bypass - ANS-Bug that allows authentication even
when password provided is incorrect.
DoS - ANS-Denial of Service
DDoS (Distributed Denial of Service) - ANS-An attack on a computer or network
device in which multiple computers send data and requests to the device in an
attempt to overwhelm it so that it cannot perform normal operations.
Passive OS fingerprinting - ANS-Observing host behavior and packets (DHCP, TCP,
etc) to determine OS
, Active OS Fingerprinting - ANS-Sends specially crafted packets to the remote OS
and analyzes the received response.
AES (Advanced Encryption Standard) - ANS-A block cipher created in the late 1990s
that uses a 128-bit block size and a 128-, 192-, or 256-bit key size. Practically
uncrackable.
TKIP (Temporal Key Integrity Protocol) - ANS-A security protocol created by the
IEEE 802.11i task group to replace WEP.
SMTP User Enumeration - ANS-EXPN VRFY
Sendmail < 8.12.9 Buffer Overflow - ANS-The prescan function in Sendmail 8.12.9
allows remote attackers to execute arbitrary code via buffer overflow attacks.
RPC (Remote Procedure Call) Enumeration - ANS-Can be assessed using
portmapper requests.
Non-Persistent XSS - ANS-XSS that occurs when the attacker's script that is
injected is not stored in the backend.
Persistent XSS - ANS-Malicious code that remains on a website until it is removed.
SOAP - ANS-Simple Object Access Protocol
Simple Object Access Protocol (SOAP) - ANS-An XML-based communication
protocol used for sending messages between applications via the Internet.
XML injection - ANS-An attack that injects XML tags and data into a database.
XXE (XML External Entity) Attack - ANS-This attack occurs when XML input
containing a reference to an external entity is processed by a weakly configured
XML parser.
Denial of Service (DoS) - ANS-An attack that disrupts the normal functioning of a
targeted server, service, or network by overwhelming it with a flood of traffic.
Buffer overflow attacks - ANS-Exploits that involve writing more data to a buffer
than it can hold, potentially allowing attackers to execute arbitrary code.
Attacks on vulnerable scripts - ANS-Exploits that target weaknesses in web scripts
to gain unauthorized access or cause harm.
URL manipulation - ANS-The process of altering a URL to gain unauthorized
access or extract sensitive information.