1|Page
CREST CPSA EXAM QUESTIONS AND VERIFIED
ANSWERS ALREADY GRADED A+
Squid - CORRECT Proxy3128
ANSWER>>
Benefits of a Penetration Test- - CORRECT Enhancement of the
management system ANSWER>>
- Avoid fines
- Protection from financial damage
- Customer protection
Structure of a Penetration - CORRECT TestPlanning and Preparation
Reconnaissance ANSWER>>
Discovery
Analyzing information and risks
Active intrusion attempts
Final analysis Report
Preparation
Another Structure of a Penetration - CORRECT TestReconnaissance
Vulnerability Scanning ANSWER>>
Investigation
Exploitation
Infrastructure - CORRECT TestingIncludes all internal computer
systems, associated ANSWER>> external devices, internet networking,
cloud and virtualization testing.
Types of Infrastructure - CORRECT Testing- External
Infrastructure ANSWER>>
Penetration Testing
- Internal Infrastructure Penetration Testing
2|Page
- Cloud and Virtualization Penetration Testing
- Wireless Security Penetration Testing
External Infrastructure - CORRECT TestingMapping flaws in the
external infrastructure ANSWER>>
Benefits of External Infrastructure Testing- Identifies - CORRECT
flaws within the firewall configuration that could be ANSWER>>
misused. - Finds how information could be leaked out
from the system
,- Suggests how these issues could be fixed
- Prepares a comprehensive report highlighting the security risk of the networks and
suggests solutions
- Ensures overall efficiency and productivity of your
business - CORRECT
Benefits of Internal Infrastructure ANSWER>> Testing- Identifies
how
an internal attacker could take advantage of even a minor security flaw
- Identifies the potential business risk and damage that an internal attacker can
inflict
- Improves security systems of internal infrastructure
- Prepares a comprehensive report giving details of the security exposures of internal
networks along with the detailed action plan on how to
deal with it Benefits of Cloud and Virtualization - CORRECT
Penetration Testing- ANSWER>>
Discover the real risks within the virtual environment and suggests the methods
and costs to fix the threats and flaws
- Provides guidelines and an action plan how to resolve the issues
- Improves the overall protection systems
- Prepares a comprehensive security system report of the cloud computing and
virtualization, outline the security flaws, causes and possible
solutions - CORRECT
Benefits of Wireless Security Penetration ANSWER>> Testing- To
find
the potential risk caused by your wireless device
3|Page
- To provide guidelines and an action plan on how to protect from the external
threats
- For preparing a comprehensive security system report of the wireless networking,
to outline the security flaw, causes, and possible solutions
Black Box - CORRECT TestingBlack-box testing is a method in
which the tester ANSWER>> is provided no information about the
application being tested.
Advantages of Black Box - CORRECT Testing- Test is generally
conducted with the perspective ANSWER>> of a user,
not the designer - Verifies contradictions in the actual system and
the specifications
Disadvantages of Black Box Penetration - CORRECT Testing-
Particularly, these kinds of test cases are ANSWER>> difficult to
design
- Possibly, it is not worth, in case designer has already conducted a test case
- It does not conduct everything
White Box Penetration TestingA tester is provided a whole
, range of information about the - CORRECT systems and/or network such
as schema, source code, os ANSWER>> details,
ip address, etc. - CORRECT
Advantages of White Box Penetration Testing- It ANSWER>> ensures
that all independent paths of a module have been exercised
- It ensures that all logical decisions have been verified along with their true and
false value.
- It discovers the typographical errors and does syntax checking - It finds the design
errors that may have occurred because of the difference between logical flow of
the program and the actual execution.
Computer Misuse Act 1990 - CORRECT HighlightsSection 1:
Unauthorized access to computer ANSWER>> material
Section 2: Unauthorized access with intent to commit or facilitate commission of
further offenses
4|Page
Section 3: Unauthorized acts with intent to impair, or with recklessness as to
impairing the operation of a computer
Human Rights Act 1998 - CORRECT Highlights- The right to life
- The right to respect for private ANSWER>> and family life
- The right to freedom of religion and belief
- Your right not to be mistreated or wrongly punished
by the state - CORRECT
Consent Information for Penetration ANSWER>> Test- Name &
Position of the individual who is providing consent
- Authorized testing period - both the date range and hours that testing is permitted
- Contact information for members of technical staff, who may provide assistance
during the test
- IP addresses or URL that are in scope of testing
- Exclusions to certain hosts, services or areas within application testing
- Credentials that may be required as part of authenticated
application testing - CORRECT
Data Protection Act 1998 ANSWER>> Highlights- Personal
data must be processed fairly and lawfully
- be obtained only for lawful purposes and not processed in any manner
incompatible with those purposes - be adequate, relevant and not excessive
- be accurate and current
- not be retained for longer than necessary
- be processed in accordance with the rights and freedoms of data subjects - Be
protected against unauthorized or unlawful processing and against accidental loss,
destruction or damage
Police and Justice Act 2006 - CORRECT Highlights- Make
amendments ANSWER>>
CREST CPSA EXAM QUESTIONS AND VERIFIED
ANSWERS ALREADY GRADED A+
Squid - CORRECT Proxy3128
ANSWER>>
Benefits of a Penetration Test- - CORRECT Enhancement of the
management system ANSWER>>
- Avoid fines
- Protection from financial damage
- Customer protection
Structure of a Penetration - CORRECT TestPlanning and Preparation
Reconnaissance ANSWER>>
Discovery
Analyzing information and risks
Active intrusion attempts
Final analysis Report
Preparation
Another Structure of a Penetration - CORRECT TestReconnaissance
Vulnerability Scanning ANSWER>>
Investigation
Exploitation
Infrastructure - CORRECT TestingIncludes all internal computer
systems, associated ANSWER>> external devices, internet networking,
cloud and virtualization testing.
Types of Infrastructure - CORRECT Testing- External
Infrastructure ANSWER>>
Penetration Testing
- Internal Infrastructure Penetration Testing
2|Page
- Cloud and Virtualization Penetration Testing
- Wireless Security Penetration Testing
External Infrastructure - CORRECT TestingMapping flaws in the
external infrastructure ANSWER>>
Benefits of External Infrastructure Testing- Identifies - CORRECT
flaws within the firewall configuration that could be ANSWER>>
misused. - Finds how information could be leaked out
from the system
,- Suggests how these issues could be fixed
- Prepares a comprehensive report highlighting the security risk of the networks and
suggests solutions
- Ensures overall efficiency and productivity of your
business - CORRECT
Benefits of Internal Infrastructure ANSWER>> Testing- Identifies
how
an internal attacker could take advantage of even a minor security flaw
- Identifies the potential business risk and damage that an internal attacker can
inflict
- Improves security systems of internal infrastructure
- Prepares a comprehensive report giving details of the security exposures of internal
networks along with the detailed action plan on how to
deal with it Benefits of Cloud and Virtualization - CORRECT
Penetration Testing- ANSWER>>
Discover the real risks within the virtual environment and suggests the methods
and costs to fix the threats and flaws
- Provides guidelines and an action plan how to resolve the issues
- Improves the overall protection systems
- Prepares a comprehensive security system report of the cloud computing and
virtualization, outline the security flaws, causes and possible
solutions - CORRECT
Benefits of Wireless Security Penetration ANSWER>> Testing- To
find
the potential risk caused by your wireless device
3|Page
- To provide guidelines and an action plan on how to protect from the external
threats
- For preparing a comprehensive security system report of the wireless networking,
to outline the security flaw, causes, and possible solutions
Black Box - CORRECT TestingBlack-box testing is a method in
which the tester ANSWER>> is provided no information about the
application being tested.
Advantages of Black Box - CORRECT Testing- Test is generally
conducted with the perspective ANSWER>> of a user,
not the designer - Verifies contradictions in the actual system and
the specifications
Disadvantages of Black Box Penetration - CORRECT Testing-
Particularly, these kinds of test cases are ANSWER>> difficult to
design
- Possibly, it is not worth, in case designer has already conducted a test case
- It does not conduct everything
White Box Penetration TestingA tester is provided a whole
, range of information about the - CORRECT systems and/or network such
as schema, source code, os ANSWER>> details,
ip address, etc. - CORRECT
Advantages of White Box Penetration Testing- It ANSWER>> ensures
that all independent paths of a module have been exercised
- It ensures that all logical decisions have been verified along with their true and
false value.
- It discovers the typographical errors and does syntax checking - It finds the design
errors that may have occurred because of the difference between logical flow of
the program and the actual execution.
Computer Misuse Act 1990 - CORRECT HighlightsSection 1:
Unauthorized access to computer ANSWER>> material
Section 2: Unauthorized access with intent to commit or facilitate commission of
further offenses
4|Page
Section 3: Unauthorized acts with intent to impair, or with recklessness as to
impairing the operation of a computer
Human Rights Act 1998 - CORRECT Highlights- The right to life
- The right to respect for private ANSWER>> and family life
- The right to freedom of religion and belief
- Your right not to be mistreated or wrongly punished
by the state - CORRECT
Consent Information for Penetration ANSWER>> Test- Name &
Position of the individual who is providing consent
- Authorized testing period - both the date range and hours that testing is permitted
- Contact information for members of technical staff, who may provide assistance
during the test
- IP addresses or URL that are in scope of testing
- Exclusions to certain hosts, services or areas within application testing
- Credentials that may be required as part of authenticated
application testing - CORRECT
Data Protection Act 1998 ANSWER>> Highlights- Personal
data must be processed fairly and lawfully
- be obtained only for lawful purposes and not processed in any manner
incompatible with those purposes - be adequate, relevant and not excessive
- be accurate and current
- not be retained for longer than necessary
- be processed in accordance with the rights and freedoms of data subjects - Be
protected against unauthorized or unlawful processing and against accidental loss,
destruction or damage
Police and Justice Act 2006 - CORRECT Highlights- Make
amendments ANSWER>>