• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 3 fuera de 20 páginas
Examen

CREST CPSA UPDATED EXAM SCRIPT QUESTIONS AND ANSWERS GUARANTEE A.pdf

Document preview thumbnail
Vista previa 3 fuera de 20 páginas

CREST CPSA UPDATED EXAM SCRIPT QUESTIONS AND ANSWERS GUARANTEE A.pdf

Vista previa del contenido

CREST CPSA UPDATED EXAM SCRIPT QUESTIONS AND
ANSWERS GUARANTEE A+
✔✔SIP requests - ✔✔REGISTER; INVITE; ACK; BYE; CANCEL; UPDATE; REFER;
PRACK; SUBSCRIBE; NOTIFY; PUBLISH; MESSAGE; INFO; OPTIONS

✔✔IPsec security architecture - ✔✔Authentication Headers (AH)
Encapsulating Security Payloads (ESP)
Security Associations (SA) - Internet Security Association and Key Management
Protocol (ISAKMP); Internet Key Exchange (IKE and IKEv2)

✔✔LM - ✔✔all passwords are converted into uppercase before generating the hash
value

✔✔LM - ✔✔password length is limited to maximum of 14 characters

✔✔LM - ✔✔a 14-character password is broken into 7+7 characters and the hash is
calculated for the two halves separately

✔✔LM - ✔✔if the password is 7 characters or less, then the second half of hash will
always produce same constant value (AAD3B435B51404EE)

✔✔LM - ✔✔the hash value is sent to network servers without salting

✔✔LM - ✔✔uses DES

✔✔128 bits - ✔✔LAN Manager (LM) hash size:

✔✔Net-NTLM - ✔✔used for network authentication

✔✔Net-NTLM - ✔✔get these hashes when using tools like Responder or Inveigh

✔✔Net-NTLMv1 - ✔✔uses DES

✔✔Net-NTLMv2 - ✔✔uses HMAC-MD5

✔✔128 bits - ✔✔Network New Technology LAN Manager (Net-NTLM) hashes size:

✔✔NTLM - ✔✔get these hashes when dumping the SAM database of any Windows
OS, a Domain Controller's Ntds.dit database or from Mimikatz

✔✔NTLM - ✔✔uses MD4

✔✔128 bits - ✔✔New Technology LAN Manager (NTLM) hash size:

,✔✔NTLM - ✔✔You CAN perform Pass-The-Hash attacks with these hashes

✔✔Net-NTLM - ✔✔You CANNOT perform Pass-The-Hash attacks with these hashes

✔✔nbtstat; nbtscan - ✔✔NetBIOS scanning tools:

✔✔nbtstat - ✔✔a command line utility that is integrated in windows systems and it can
unveil information about the NetBIOS names and the remote machine name table or
local but only for one host

✔✔nbtscan - ✔✔a NetBIOS nameserver scanner which has the same functions as
nbtstat but it operates on a range of addresses instead of one

✔✔PEAP - ✔✔a protocol that encapsulates the Extensible Authentication Protocol
(EAP) within an encrypted and authenticated Transport Layer Security (TLS) tunnel

✔✔LEAP - ✔✔a proprietary wireless LAN authentication method developed by Cisco
Systems

✔✔LEAP - ✔✔uses WEP

✔✔stream cipher (symmetric) - ✔✔Rivest Cipher 4 (RC4)

✔✔symmetric-key block cipher - ✔✔Rivest Cipher 5 (RC5)

✔✔symmetric-key block cipher - ✔✔Data Encryption Standard (DES)

✔✔symmetric-key block cipher - ✔✔Advanced Encryption Standard (AES)

✔✔Media Access Control (MAC) address - ✔✔of a device is a unique identifier
assigned to a network interface controller (NIC)

✔✔48 bits - ✔✔Media Access Control (MAC) address size:

✔✔Oracle System ID (SID) - ✔✔used to uniquely identify a particular database on a
system

✔✔rlogin; rcp; rsh - ✔✔Berkeley r-commands that share the hosts.equiv and .rhosts
access-control scheme

✔✔permissions required for copying a file into / out of a directory - ✔✔source directory:
execute and read permission
source file: read permission

, target directory: execute and write permission
target file: you don't need any permission since it doesn't exit before you copy it. or write
permission if the file exists

✔✔blind SQL injection - ✔✔a type of SQL Injection attack that asks the database true
or false questions and determines the answer based on the applications response - this
attack is often used when the web application is configured to show generic error
messages, but has not mitigated the code that is vulnerable to SQL injection

✔✔Link-Local Multicast Name Resolution (LLMNR) - ✔✔a Microsoft Windows protocol
based on the Domain Name System (DNS) packet format that allows both IPv4 and
IPv6 hosts to perform name resolution for hosts on the same local link

✔✔Network Basic Input/Output System (NetBIOS) name service - ✔✔identifies systems
on a local network by their NetBIOS name

✔✔LLMNR spoofing - ✔✔Adversaries can spoof an authoritative source for name
resolution on a victim network by responding to LLMNR (UDP 5355)/NBT-NS (UDP
137) traffic as if they know the identity of the requested host, effectively poisoning the
service so that the victims will communicate with the adversary controlled system. If the
requested host belongs to a resource that requires identification/authentication, the
username and NTLMv2 hash will then be sent to the adversary controlled system.

✔✔FTP bounce attack - ✔✔an exploit of the FTP protocol whereby an attacker is able
to use the PORT command to request access to ports indirectly through the use of the
victim machine as a middle man for the request

✔✔Ntds.dit file - ✔✔a database that stores Active Directory data, including information
about user objects, groups, and group membership - it includes the password hashes
for all users in the domain

✔✔computer worm - ✔✔What is Code Red?

✔✔Internet Information Services (IIS) 5.0 - ✔✔MS01-033 basis

✔✔Code Red - ✔✔The MS01-033 vulnerability was used by which malware?

✔✔computer worm - ✔✔What is Conficker?

✔✔Conficker - ✔✔The MS08-067 vulnerability was used by which malware?

✔✔computer worm - ✔✔What is Blaster?

✔✔Distributed Component Object Model (DCOM) - ✔✔MS03-026 basis

Información del documento

Subido en
10 de enero de 2026
Número de páginas
20
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$12.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
EXAMCAFE
3.5
(41)
Vendido
290
Seguidores
11
Artículos
36202
Última venta
3 días hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes