• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 51 páginas
Examen

CREST CPSA WRITTEN EXAM WITH 300+ QUESTIONS AND CORRECT ANSWERS LATEST (VERIFIED ANSWERS)

Document preview thumbnail
Vista previa 4 fuera de 51 páginas

CREST CPSA WRITTEN EXAM WITH 300+ QUESTIONS AND CORRECT ANSWERS LATEST (VERIFIED ANSWERS) What are the benefits of a penetration test? - Correct Answer: - Enhancement of the management system - Avoid fines - Protection from financial damage - Customer protection What is the structure of a penetration test? - --- ANSWERPlanning and Preparation Reconnaissance Discovery Analyzing information and risks Active intrusion attempts Final analysis Report Preparation What is another structure of a penetration test? - --- ANSWERReconnaissance Vulnerability Scanning Investigation Exploitation What is does infrastructure testing include? - --- ANSWERIncludes all internal computer systems, associated external devices, internet networking, cloud and virtualization testing. What are the types of infrastructure testing? - Correct Answer: - External Infrastructure Penetration Testing - Internal Infrastructure Penetration Testing - Cloud and Virtualization Penetration Testing - Wireless Security Penetration Testing What does External Infrastructure Testing include? - --- ANSWERMapping flaws in the external infrastructure What are the benefits of External Infrastructure Testing ? - --- ANSWER- Identifies flaws within the firewall configuration that could be misused. - Finds how information could be leaked out from the system - Suggests how these issues could be fixed - Prepares a comprehensive report highlighting the security risk of the networks and suggests solutions - Ensures overall efficiency and productivity of your business What are the benefits of Internal Infrastructure testing? - --- ANSWER-Identifies how an internal attacker could take advantage of even a minor security flaw - Identifies the potential business risk and damage that an internal attacker can inflict - Improves security systems of internal infrastructure - Prepares a comprehensive report giving details of the security exposures of internal networks along with the detailed action plan on how to deal with it What are the benefits of cloud and virtualization penetration testing? - Correct Answer: - Discover the real risks within the virtual environment and suggests the methods and costs to fix the threats and flaws - Provides guidelines and an action plan how to resolve the issues - Improves the overall protection systems - Prepares a comprehensive security system report of the cloud computing and virtualization, outline the security flaws, causes and possible solutions What are the benefits of wireless security penetration testing ? - -- -ANSWER- To find the potential risk caused by your wireless device - To provide guidelines and an action plan on how to protect from the external threats - For preparing a comprehensive security system report of the wireless networking, to outline the security flaw, causes, and possible solutions What is Black Box Testing? - Correct Answer: Black-box testing is a method in which the tester is provided no information about the application being tested. What are the advantages of Black Box Testing? - --- ANSWER- Test is generally conducted with the perspective of a user, not the designer - Verifies contradictions in the actual system and the specifications What are the disadvantages of black box penetration testing? - --- ANSWER- Particularly, these kinds of test cases are difficult to design - Possibly, it is not worth, in-case designer has already conducted a test case - It does not conduct everything What is white box penetration testing ? - Correct Answer: A tester is provided a whole range of information about the systems and/or network such as schema, source code, os details, ip address, etc. What are the advantages of white box penetration testing? - --- ANSWER- It ensures that all independent paths of a module have been exercised - It ensures that all logical decisions have been verified along with their true and false value. - It discovers the typographical errors and does syntax checking - It finds the design errors that may have occurred because of the difference between logical flow of the program and the actual execution. What are the important highlights of the computer misuse act 1990? - Correct Answer: Section 1: Unauthorized access to computer material Section 2: Unauthorized access with intent to commit or facilitate commission of further offenses Section 3: Unauthorized acts with intent to impair, or with recklessness as to impairing the operation of a computer Unauthorized modification of computer material What are the important highlights of the human rights act 1998? - Correct Answer: - The right to life - The right to respect for private and family life - The right to freedom of religion and belief - Your right not to be mistreated or wrongly punished by the state when capturing the scope of a penetration test, what information requires consent to meet the UK laws? - Correct Answer: -Name & Position of the individual who is providing consent -Authorized testing period - both the date range and hours that testing is permitted - Contact information for members of technical staff, who may provide assistance during the test - IP addresses or URL that are in scope of testing - Exclusions to certain hosts, services or areas within application testing Credentials that may be required as part of authenticated application testing What are the important highlights of the data protection act 1998? - Correct Answer: - Personal data must be processed fairly and lawfully - be obtained only for lawful purposes and not processed in any manner incompatible with those purposes - be adequate, relevant and not excessive - be accurate and current - not be retained for longer than neccessary - be processed in accordance with the rights and freedoms of data subjects - Be protected against unauthorized or unlawful processing and against accidental loss, destruction or damage What are the important highlights of the police and justice act 2006? - Correct Answer: - Make amendments to the computer misuse act 1990 - increased penalties of computer misuse act (makes unauthorized computer access serious enough to fall under extradition) - Made it illegal to perform DOS attacks - Made it illegal to supply and own hacking tools. - Be careful about how you release information about exploits. What issues may arise between a tester and his client? - --- ANSWER- The tester is unknown to his client - so, on what grounds, he should be given access of sensitive data -Who will take the guarantee of security of lost data? - The client may blame for the loss of data or confidentiality to tester. How can you prevent legal issues when doing a penetration test? - Correct Answer: A statement of intent should be duly signed by both parties - The tester has the permission in writing, with clearly defined parameters - the company has the details of its pen tester and an assurance that he would not leak any confidential data What does scoping a penetration test involve? - Correct Answer: - All relevant risk owners - Technical staff knowledgeable about the target system - A representative of the penetration test team - Risk owners should outline any areas of special concern - Technical staff should outline technical boundaries of the organizations IT estate - The penetration test team should identify what testing they believe will give a full picture of the vulnerability status of the estate What is a IP protocol? - Correct Answer: The IP (Internet Protocol) is the network layer communications protocol in the Internet protocol suite used for relaying datagrams across network boundaries What is the TCP protocol? - Correct Answer: TCP (transmisson control protocol) a main protocol from the Internet protocol suite. What is the Task of TCP? - Correct Answer: To create a connection between the client and server before data can be sent. What will applications that do not require a reliable data stream use? - Correct Answer: User datagram protocol What is the task of the Internet Protocol? - Correct Answer: to deliver packets from the source host to the destination host based on the IP addresses in the packet headers. Is UDP part of the Internet protocol suite? - Correct Answer: Yes What does SYN do in a TCP handshake? - Correct Answer: SYN is used to initiate and establish a connection. It also helps you to synchronize sequence numbers between devices. Does UDP perform handshakes? - Correct Answer: No What does ACK do in TCP handshake? - Correct Answer: Helps to confirm to the other side that it has received the SYN. Which protocol is known for performing a three way handshake? - Correct Answer: TCP What happens after the SYN and ACK phrases of a TCP handshake? - Correct Answer: SYN-ACK What does SYN-ACK do in TCP handshake? - --- ANSWERSYN-ACK is a SYN message from local device and ACK of the earlier packet. What is FIN used for? - Correct Answer: Used to terminate the connection What does SYN stand for in TCP? - Correct Answer: Synchronize What does ACK stand for in TCP? - --- ANSWERAcknowledgement What does SYN-ACK stand for in TCP - --- ANSWERSynchronize Acknowledgement What does FIN stand for in TCP? - Correct Answer: Finish What happens after the SYN-ACK phrase? - Correct Answer: FIN What does TCP stand for ? - Correct Answer: Transmission control protocol What is port 9100? - Correct Answer: Jetdirect What is port 567? - Correct Answer: DHCPv6 (servers) What is port 593? - Correct Answer: RPC over HTTPS What port is 49? - Correct Answer: TACACS What does TACACS stand for? - Terminal Access Control of Authentication and Control Systems - Terminal Access Controller Access Control System - Television Availability Control And Communication Standard - Teletype Authentication and Control of All Control Systems - --- ANSWERTerminal Access Controller Access Control System What port is NTP? - Correct Answer: 123 What is Port 500? - Correct Answer: Internet Security Association and Key Management Protocol - Key exchange What port is syslog? - Correct Answer: 514 What port is RIP? - Correct Answer: 520 What is port 587? - Correct Answer: SMTP What UDP port does SMTP use? - Correct Answer: 587 What is port 1521 - Correct Answer: Oracle What is port 6000 - Correct Answer: X11 What port is FTP - Correct Answer: 21 What does UDP stand for? - Correct Answer: User Datagram Protocol What is port 389? - Correct Answer: LDAP What port is 514 - Correct Answer: Syslog What is port 587? - Correct Answer: SMTP What port is for DHCPv6 (servers) - Correct Answer: 567 What does DHCP stand for? - Correct Answer: Dynamic Host Configuration Protocol What is the port of SSH - Correct Answer: 22 What port is Kerberos? - Correct Answer: 88 What port is POP3 - Correct Answer: 110 what port is RPC? - Correct Answer: 111 What does SMB stand for? - Correct Answer: Server Message Block

Vista previa del contenido

CREST CPSA WRITTEN EXAM WITH 300+ QUESTIONS AND
CORRECT ANSWERS LATEST 2023-2024(VERIFIED ANSWERS)



What are the benefits of a penetration test? - Correct Answer: - Enhancement of the
management system
- Avoid fines
- Protection from financial damage
- Customer protection
What is the structure of a penetration test? - --- ANSWER>>>Planning and
Preparation Reconnaissance
Discovery
Analyzing information and risks Active intrusion
attempts
Final analysis Report
Preparation

What is another structure of a penetration test? - --- ANSWER>>>Reconnaissance
Vulnerability Scanning
Investigation Exploitation

,What is does infrastructure testing include? - --- ANSWER>>>Includes all internal computer
systems, associated external devices, internet networking, cloud and virtualization testing.

What are the types of infrastructure testing? - Correct Answer: - External Infrastructure
Penetration Testing
- Internal Infrastructure Penetration Testing
- Cloud and Virtualization Penetration Testing
- Wireless Security Penetration Testing
What does External Infrastructure Testing include? - --- ANSWER>>>Mapping flaws in the
external infrastructure

What are the benefits of External Infrastructure Testing ? - --- ANSWER>>>- Identifies flaws
within the firewall configuration that could be misused.
- Finds how information could be leaked out from the system
- Suggests how these issues could be fixed
- Prepares a comprehensive report highlighting the security risk of the networks and suggests
solutions
- Ensures overall efficiency and productivity of your business

What are the benefits of Internal Infrastructure testing? - --- ANSWER>>>-Identifies
how an internal attacker could take advantage of even a minor security flaw
- Identifies the potential business risk and damage that an internal attacker can inflict
- Improves security systems of internal infrastructure
- Prepares a comprehensive report giving details of the security exposures of internal networks
along with the detailed action plan on how to deal with it

What are the benefits of cloud and virtualization penetration testing? - Correct Answer: - Discover
the real risks within the

,virtual environment and suggests the methods and costs to fix the threats and flaws
- Provides guidelines and an action plan how to resolve the issues
- Improves the overall protection systems
- Prepares a comprehensive security system report of the cloud computing and
virtualization, outline the security flaws, causes and possible solutions

What are the benefits of wireless security penetration testing ? - --
-ANSWER>>>- To find the potential risk caused by your wireless device
- To provide guidelines and an action plan on how to protect from the external threats
- For preparing a comprehensive security system report of the wireless networking, to
outline the security flaw, causes, and possible solutions

What is Black Box Testing? - Correct Answer: Black-box testing is a method in which the tester
is provided no information about the application being tested.

What are the advantages of Black Box Testing? - --- ANSWER>>>- Test is generally conducted
with the perspective of a user, not the designer
- Verifies contradictions in the actual system and the specifications
What are the disadvantages of black box penetration testing? - --- ANSWER>>>- Particularly,
these kinds of test cases are difficult to design
- Possibly, it is not worth, in-case designer has already conducted a test case
- It does not conduct everything

, What is white box penetration testing ? - Correct Answer: A tester is provided a whole range of
information about the systems and/or network such as schema, source code, os details, ip
address, etc.


What are the advantages of white box penetration testing? - --- ANSWER>>>- It ensures
that all independent paths of a module have been exercised
- It ensures that all logical decisions have been verified along with their true and false value.
- It discovers the typographical errors and does syntax checking
- It finds the design errors that may have occurred because of the difference between logical
flow of the program and the actual execution.

What are the important highlights of the computer misuse act 1990? - Correct Answer: Section
1: Unauthorized access to computer material
Section 2: Unauthorized access with intent to commit or facilitate commission of further offenses
Section 3: Unauthorized acts with intent to impair, or with recklessness as to impairing the
operation of a computer

Unauthorized modification of computer material

What are the important highlights of the human rights act 1998? -
Correct Answer: - The right to life
- The right to respect for private and family life
- The right to freedom of religion and belief
- Your right not to be mistreated or wrongly punished by the state
when capturing the scope of a penetration test, what information requires consent to meet the
UK laws? - Correct Answer: -Name & Position of the individual who is providing consent
-Authorized testing period - both the date range and hours that testing is permitted

Información del documento

Subido en
17 de agosto de 2024
Número de páginas
51
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$13.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Nurslink
3.5
(27)
Vendido
238
Seguidores
72
Artículos
1714
Última venta
23 horas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes