CREST CPSA END OF COURSE EXAMS QUESTIONS AND
ANSWERS GUARANTEE A+
✔✔Default SSH Creds for Cisco - ✔✔admin, cisco, enable, hsa, pix, pnadmin, ripeop,
root, shelladmin : admin, Admin123, default, password, secure4u, cisco, Cisco, _Cisco,
cisco123, C1sco!23, Cisco123, Cisco1234, TANDERBERG, change_it, 12345, ipics,
pnadmin, diamond, hsadb,c, cc, attack, blender, changeme
✔✔Default SSH Creds for Citrix - ✔✔root, nsrootm nsmaint, vdiadmin, kvm, cli, admin :
C1trix321, nsroot, nsroot, nsmaint, kaviza, kvaiza123, freebsd, public, rootadmin,
wanscaler
✔✔Default SSH Creds for D-Link - ✔✔admin, user : private, admin, user
✔✔Default SSH Creds for Dell - ✔✔root, user1, admin, vkernel, cli : calvin, 123456,
password, vkernel, Stor@ge!, admin
✔✔Default SSH Creds for EMC - ✔✔admin , root, sysadmin : EMCPMAdm7n,
Password#1, Password123#, sysadmin, changeme, emc
✔✔Default SSH Creds for Oracle - ✔✔root, oracle, oravis, applvis, ilom-admin, ilom-
operator, nm2user : changeme, ilom-admin, ilom=operator, welcome1, oracle
✔✔Default SSH Creds for VMware - ✔✔vi-admin, root, hqadmin, vmware, admin :
vmware, vmw@re, hqadmin, default
✔✔Default SSH Creds for NetApp - ✔✔admin:netapp123
✔✔Default SSH Creds for Juniper - ✔✔netscreen:netscreen
✔✔What are BMCs? - ✔✔Baseboard Management Controllers are embedded
computers that provide out of band monitoring for desktops and servers. They are sold
under many brand names.
These devices often expose an IPMI service under the UDP Port 623.
✔✔RAKP - ✔✔RMCP + Authenticated Key-Exchange Protocol
✔✔What are the two main vulnerabilities associated with IPMI Protocol? - ✔✔Remote
Hash Retrieval via RAKP and Zero Cipher Authentication Bypass
✔✔SOA - ✔✔Start of Authority
✔✔NS - ✔✔Name Server
, ✔✔A (Address) - ✔✔IPv4 Address for a hostname
✔✔AAAA (Address) - ✔✔IPv6 Address for a hostname
✔✔PTR - ✔✔Hostname of a given IPv4 or IPv6 Address
✔✔CNAME - ✔✔Canonical Name (Hostname which the CNAME is an alias of)
✔✔MX - ✔✔Mail Exchange (Mail Servers for a given domain)
✔✔HINFO - ✔✔Host information record includes CPU type and OS
✔✔SRV - ✔✔Service record (SRV record) is a specification of data in the Domain
Name System defining the location, i.e., the hostname and port number, of servers for
specified services. Includes service endpoints within a domain, including Kerberos,
LDAP, SIP, and XMPP
✔✔TXT - ✔✔Materials including SPF and DKIM fields used to provide security,
depending on configuration
✔✔Which nmap flag can be used to further enumerate SRV records for a domain? -
✔✔We can use --script dns-srv-enum --script-args dns-srv-enum.domain=<DOMAIN>
✔✔Which port is used when performing a DNS Zone Transfer Attack? - ✔✔TCP 53
✔✔mDNS - ✔✔Multicast DNS (used to discover items on a network without real DNS)
Apple Bonjour
Uses UDP 5353
✔✔MIB - ✔✔Management Information Base
✔✔What are the types of LDAP Authentication? - ✔✔Simple Authentication using
plaintext credentials or Simple Authentication and Security Layer (SASL) provides
support for mechanisms including DIGEST-MD% and CRAM-MD5
✔✔CRAM-MD5 - ✔✔Challenge-Response Authentication Mechanism-Message Digest
5
This method is susceptible to known plaintext attack by which tools, including Cain and
Abel, can crack passwords upon sniffing challenge-response data.
✔✔DIGEST-MD5 - ✔✔In this authentication mechanism, the server sends a challenge
and nonce value, which is then hashed by a client using a key derived from a
combination of username, password, and realm.
ANSWERS GUARANTEE A+
✔✔Default SSH Creds for Cisco - ✔✔admin, cisco, enable, hsa, pix, pnadmin, ripeop,
root, shelladmin : admin, Admin123, default, password, secure4u, cisco, Cisco, _Cisco,
cisco123, C1sco!23, Cisco123, Cisco1234, TANDERBERG, change_it, 12345, ipics,
pnadmin, diamond, hsadb,c, cc, attack, blender, changeme
✔✔Default SSH Creds for Citrix - ✔✔root, nsrootm nsmaint, vdiadmin, kvm, cli, admin :
C1trix321, nsroot, nsroot, nsmaint, kaviza, kvaiza123, freebsd, public, rootadmin,
wanscaler
✔✔Default SSH Creds for D-Link - ✔✔admin, user : private, admin, user
✔✔Default SSH Creds for Dell - ✔✔root, user1, admin, vkernel, cli : calvin, 123456,
password, vkernel, Stor@ge!, admin
✔✔Default SSH Creds for EMC - ✔✔admin , root, sysadmin : EMCPMAdm7n,
Password#1, Password123#, sysadmin, changeme, emc
✔✔Default SSH Creds for Oracle - ✔✔root, oracle, oravis, applvis, ilom-admin, ilom-
operator, nm2user : changeme, ilom-admin, ilom=operator, welcome1, oracle
✔✔Default SSH Creds for VMware - ✔✔vi-admin, root, hqadmin, vmware, admin :
vmware, vmw@re, hqadmin, default
✔✔Default SSH Creds for NetApp - ✔✔admin:netapp123
✔✔Default SSH Creds for Juniper - ✔✔netscreen:netscreen
✔✔What are BMCs? - ✔✔Baseboard Management Controllers are embedded
computers that provide out of band monitoring for desktops and servers. They are sold
under many brand names.
These devices often expose an IPMI service under the UDP Port 623.
✔✔RAKP - ✔✔RMCP + Authenticated Key-Exchange Protocol
✔✔What are the two main vulnerabilities associated with IPMI Protocol? - ✔✔Remote
Hash Retrieval via RAKP and Zero Cipher Authentication Bypass
✔✔SOA - ✔✔Start of Authority
✔✔NS - ✔✔Name Server
, ✔✔A (Address) - ✔✔IPv4 Address for a hostname
✔✔AAAA (Address) - ✔✔IPv6 Address for a hostname
✔✔PTR - ✔✔Hostname of a given IPv4 or IPv6 Address
✔✔CNAME - ✔✔Canonical Name (Hostname which the CNAME is an alias of)
✔✔MX - ✔✔Mail Exchange (Mail Servers for a given domain)
✔✔HINFO - ✔✔Host information record includes CPU type and OS
✔✔SRV - ✔✔Service record (SRV record) is a specification of data in the Domain
Name System defining the location, i.e., the hostname and port number, of servers for
specified services. Includes service endpoints within a domain, including Kerberos,
LDAP, SIP, and XMPP
✔✔TXT - ✔✔Materials including SPF and DKIM fields used to provide security,
depending on configuration
✔✔Which nmap flag can be used to further enumerate SRV records for a domain? -
✔✔We can use --script dns-srv-enum --script-args dns-srv-enum.domain=<DOMAIN>
✔✔Which port is used when performing a DNS Zone Transfer Attack? - ✔✔TCP 53
✔✔mDNS - ✔✔Multicast DNS (used to discover items on a network without real DNS)
Apple Bonjour
Uses UDP 5353
✔✔MIB - ✔✔Management Information Base
✔✔What are the types of LDAP Authentication? - ✔✔Simple Authentication using
plaintext credentials or Simple Authentication and Security Layer (SASL) provides
support for mechanisms including DIGEST-MD% and CRAM-MD5
✔✔CRAM-MD5 - ✔✔Challenge-Response Authentication Mechanism-Message Digest
5
This method is susceptible to known plaintext attack by which tools, including Cain and
Abel, can crack passwords upon sniffing challenge-response data.
✔✔DIGEST-MD5 - ✔✔In this authentication mechanism, the server sends a challenge
and nonce value, which is then hashed by a client using a key derived from a
combination of username, password, and realm.