CREST CPSA (Practitioner Security Analyst)

Windows Security Assessment

24 practice questions with explanations — 15 free to try

2 of these 24 questions are in the free 15-question taster · the full topic is part of Premium

PassNova has 24 CREST CPSA (Practitioner Security Analyst) practice questions on Windows Security Assessment, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Windows Security Assessment: example questions & answers

2 worked examples with answers and explanations below. Try 15 CREST CPSA (Practitioner Security Analyst) questions free in the browser; the full 24-question Windows Security Assessment bank is part of PassNova Premium.

  1. A tester enumerates a Windows host over SMB and lists its shares, finding one named 'IPC$'. What is the IPC$ share used for?

    • AA share that automatically grants administrative access when mounted
    • BA hidden share holding the password hashes of the host's local accounts, used for remote backup
    • CThe default location where all printer drivers are published
    • DAn inter-process communication share used for named-pipe sessions, including anonymous enumeration✓

    Answer: IPC$ is the inter-process communication share that supports named pipes and is historically the channel for null-session enumeration of users, groups and shares. It does not store password hashes, is not the printer-driver store, and mounting it does not grant admin rights.

  2. A tester establishes a connection to \\target\IPC$ using a blank username and blank password. Which technique is this, and why does it matter?

    • AA DNS zone transfer, copying the domain's records to the tester
    • BA pass-the-hash attack, authenticating with an NTLM hash that was taken earlier from the target host's own memory
    • CA Kerberos golden ticket, granting domain-wide administrative rights covering every host across the whole forest
    • DA null session, which on unhardened systems can enumerate users, groups and shares anonymously✓

    Answer: Connecting to IPC$ with empty credentials is a null session, and on systems that permit anonymous access it can reveal account names, group memberships and shares. It is not a Kerberos golden ticket, not pass-the-hash (which uses a real hash), and not a DNS zone transfer.

Start practising Windows Security Assessment →