Windows Security Assessment
24 practice questions with explanations — 15 free to try
2 of these 24 questions are in the free 15-question taster · the full topic is part of Premium
PassNova has 24 CREST CPSA (Practitioner Security Analyst) practice questions on Windows Security Assessment, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Windows Security Assessment: example questions & answers
2 worked examples with answers and explanations below. Try 15 CREST CPSA (Practitioner Security Analyst) questions free in the browser; the full 24-question Windows Security Assessment bank is part of PassNova Premium.
A tester enumerates a Windows host over SMB and lists its shares, finding one named 'IPC$'. What is the IPC$ share used for?
- AA share that automatically grants administrative access when mounted
- BA hidden share holding the password hashes of the host's local accounts, used for remote backup
- CThe default location where all printer drivers are published
- DAn inter-process communication share used for named-pipe sessions, including anonymous enumeration✓
Answer: IPC$ is the inter-process communication share that supports named pipes and is historically the channel for null-session enumeration of users, groups and shares. It does not store password hashes, is not the printer-driver store, and mounting it does not grant admin rights.
A tester establishes a connection to \\target\IPC$ using a blank username and blank password. Which technique is this, and why does it matter?
- AA DNS zone transfer, copying the domain's records to the tester
- BA pass-the-hash attack, authenticating with an NTLM hash that was taken earlier from the target host's own memory
- CA Kerberos golden ticket, granting domain-wide administrative rights covering every host across the whole forest
- DA null session, which on unhardened systems can enumerate users, groups and shares anonymously✓
Answer: Connecting to IPC$ with empty credentials is a null session, and on systems that permit anonymous access it can reveal account names, group memberships and shares. It is not a Kerberos golden ticket, not pass-the-hash (which uses a real hash), and not a DNS zone transfer.