โ† All CPSA Flashcard Decks

Crest Flashcards

7 cards from real CPSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Crest flashcards as text
  1. What does CVSS Base Score measure in the context of vulnerability assessment?

    Answer: The intrinsic severity of a vulnerability independent of time and environment

    The CVSS Base Score reflects the intrinsic qualities of a vulnerability (attack vector, complexity, privileges required, impact) without considering time or environmental factors.

  2. What is a pass-the-hash attack and which protocol does it primarily target?

    Answer: Authenticating using a stolen password hash without cracking it; targets NTLM

    Pass-the-hash exploits NTLM authentication by using a captured hash directly as a credential, bypassing the need to know the plaintext password.

  3. Which Windows privilege escalation technique exploits services running with unquoted paths containing spaces?

    Answer: Unquoted service path exploitation

    When a service executable path with spaces is unquoted, Windows searches each space-delimited path component, allowing an attacker to place a malicious binary in an intermediate directory.

  4. What does the term 'lateral movement' mean in the context of a penetration test?

    Answer: Moving from one compromised system to other systems in the network

    Lateral movement refers to techniques used to progressively move through a network after initial compromise, accessing additional hosts and resources.

  5. Which tool is most commonly associated with Active Directory enumeration and attack path visualization during internal penetration tests?

    Answer: BloodHound

    BloodHound collects AD data via SharpHound and visualizes attack paths, identifying the shortest path to Domain Admin through ACL abuse, group memberships, and trust relationships.

  6. What distinguishes a credentialed vulnerability scan from an uncredentialed scan?

    Answer: Credentialed scans authenticate to target systems and report installed software and patch levels

    Credentialed scans log into target systems using provided credentials, allowing them to enumerate installed packages, missing patches, and configuration issues that unauthenticated scans cannot detect.

  7. What is the primary purpose of Mimikatz during a Windows penetration test?

    Answer: Extracting plaintext passwords and hashes from Windows memory (LSASS)

    Mimikatz reads credentials including NTLM hashes and, where WDigest is enabled, plaintext passwords from the LSASS process memory on Windows systems.