CREST Registered Penetration Tester (CRT) Certification Sample Questions

Registered Penetration Tester Dumps, CRT Dumps, CRT PDF, Registered Penetration Tester VCE, CREST CRT VCE, CREST Registered Penetration Tester PDFThe purpose of this Sample Question Set is to provide you with information about the CREST Registered Penetration Tester exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CRT certification test. To get familiar with real exam environment, we suggest you try our Sample CREST Registered Penetration Tester Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual CREST Registered Penetration Tester (CRT) certification exam.

These sample questions are simple and basic questions that represent likeness to the real CREST CRT exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium CREST Registered Penetration Tester Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

CREST CRT Sample Questions:

01. Which of the following are commonly used web application reconnaissance tools?
(Choose two.)
a) Hydra
b) Ncat
c) Dirb
d) gobuster
 
02. Which database system is most commonly used in WordPress installations?
a) Microsoft SQL Server
b) MySQL
c) PostgreSQL
d) Oracle
 
03. An SSH server offers a subsystem that provides an interactive, FTP-like session over the existing SSH channel, with directory listings, renames, deletes and resumable transfers.
What is that subsystem called?
a) SFTP
b) FTPS
c) TFTP
d) SCP
 
04. What is the primary purpose of the /etc/sudoers file?
a) To configure logging
b) To store user home directories
c) To define password complexity
d) To manage user sudo permissions
 
05. What kind of information can a WHOIS lookup provide during reconnaissance?
a) Server operating system
b) Open ports
c) Domain owner details
d) Website technologies
 
06. Which tool enumerates DNS information passively, without sending queries to the target's own name servers?
a) theHarvester
b) nslookup
c) dig
d) dnsrecon
 
07. The default port for MySQL is ______.
a) 5432
b) 1521
c) 1433
d) 3306
 
08. Which TCP port does SSH listen on by default?
a) 21
b) 443
c) 22
d) 110
 
09. What are valid reasons for performing DNS reconnaissance?
(Choose two.)
a) Mapping out a target's subdomains
b) Extracting internal hostnames
c) Identifying domain registrars
d) Determining which security patches are missing on the discovered hosts
 
10. What is the primary purpose of OS fingerprinting during a penetration test?
a) To enumerate the TCP and UDP ports the host has open
b) To bypass the firewall rules protecting the host
c) To determine which operating system patches are missing
d) To establish which operating system the host is running

Answers:

Question: 01
Answer: c, d
Question: 02
Answer: b
Question: 03
Answer: a
Question: 04
Answer: d
Question: 05
Answer: c
Question: 06
Answer: a
Question: 07
Answer: d
Question: 08
Answer: c
Question: 09
Answer: a, b
Question: 10
Answer: d

Note: For any error in CREST Registered Penetration Tester (CRT) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (111 votes)