Crest Flashcards
7 cards from real CPSA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Crest flashcards as text
What is the primary purpose of defining scope before a CREST penetration test engagement?
Answer: To legally and operationally bound the systems the tester is authorized to target
Scope definition establishes the legal authorization boundary, protecting both the tester and client by clearly specifying which systems, networks, and applications are in scope.
In a CREST penetration test report, what is the primary audience and purpose of the Executive Summary?
Answer: Senior management who need a business-risk overview without technical detail
The Executive Summary communicates overall risk posture, business impact, and strategic recommendations in non-technical language suited for C-level and board-level readers.
What is the difference between a vulnerability assessment and a penetration test?
Answer: A vulnerability assessment identifies weaknesses without exploiting them; a penetration test actively exploits findings to demonstrate impact
Vulnerability assessments enumerate potential weaknesses, while penetration tests go further by actively exploiting vulnerabilities to prove real-world impact and chain attack paths.
What does PTES (Penetration Testing Execution Standard) define?
Answer: A technical standard framework covering the full lifecycle of penetration testing from pre-engagement to reporting
PTES provides a structured methodology covering seven phases: pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.
Which factor should be weighted most heavily when determining the severity rating of a finding in a penetration test report?
Answer: The combination of likelihood of exploitation and potential business impact
Severity ratings should reflect both exploitability and the real-world impact on the organization's confidentiality, integrity, and availability if exploited.
What is the correct action for a penetration tester who discovers evidence of a prior unauthorized breach during an engagement?
Answer: Immediately stop all testing and escalate to the client under agreed incident procedures
Discovering an active or prior breach is a critical event requiring immediate client notification per rules of engagement, as it may trigger a formal incident response.
What does 'gray box' testing mean in the context of a CREST assessment methodology?
Answer: Testing where the tester has partial knowledge of the target environment, such as credentials or architecture diagrams
Gray box testing provides testers with some insider information (e.g., user credentials, network diagrams) to simulate an attack from a partially informed adversary such as a malicious insider.