CREST Tester Application (CCT APP) Certification Sample Questions

Tester Application Dumps, CCT APP Dumps, CCT APP PDF, Tester Application VCE, CREST CCT APP VCE, CREST Tester Application PDFThe purpose of this Sample Question Set is to provide you with information about the CREST Tester Application exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CCT APP certification test. To get familiar with real exam environment, we suggest you try our Sample CREST Tester Application Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual CREST Certified Tester - Application (CCT APP) certification exam.

These sample questions are simple and basic questions that represent likeness to the real CREST CCT APP exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium CREST Tester Application Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

CREST CCT APP Sample Questions:

01. A DevOps team uses Terraform to provision infrastructure, and a security audit reveals that S3 buckets are being deployed with public-read access.
What is the best remediation?
a) Delete the exposed S3 bucket and its objects
b) Enable AES server-side encryption on the bucket
c) Add a WAF rule to block public requests to the bucket
d) Modify the IaC script to remove public-read and enforce private access
 
02. Which AWS service is used to define and enforce identity-based access policies?
a) IAM
b) VPC
c) EC2
d) S3
 
03. What is the primary goal of integrating security into the software development lifecycle (SDLC)?
a) To ensure compliance with marketing goals
b) To reduce the bandwidth consumed by build pipelines
c) To identify and fix vulnerabilities early in development
d) To remove the need for code review and testing
 
04. Which file stores password hashes for local users on macOS?
a) /etc/passwd
b) /var/db/dslocal/nodes/Default/users/
c) /etc/shadow
d) /var/log/auth.log
 
05. Which are recommended cryptographic best practices for secure application development?
(Choose two.)
a) Avoiding hardcoded encryption keys
b) Storing plaintext passwords for logging
c) Use of a secure random number generator
d) Enabling SSLv3 for compatibility
 
06. During a Kubernetes security review, you find that a user can run pods with hostPID: true.
What is a potential risk of this misconfiguration?
a) Direct interaction with host processes
b) Denial-of-Service via NodePort exhaustion
c) Inaccessible DNS resolution
d) Inability to restart pods
 
07. Which macOS utility can be used to manage stored credentials, certificates, and secure notes?
a) Disk Utility
b) Gatekeeper
c) Keychain Access
d) Finder
 
08. Which container platforms are commonly used in enterprise environments?
(Choose two.)
a) rclone
b) Kubernetes
c) Elasticsearch
d) Docker
 
09. What is the role of the STARTTLS command in a mail service?
a) Upgrades an unencrypted connection to an encrypted one
b) Authenticates the connecting mail client
c) Hashes the account username with MD5 before transmission
d) Switches the session to a dedicated TLS port such as 465
 
10. What is the distinguishing feature of a vishing attack?
a) Scripts embedded in an HTML form on a cloned page
b) Use of spoofed websites that mirror a login page
c) Exploitation of an unpatched browser flaw
d) Voice-based social engineering over the phone

Answers:

Question: 01
Answer: d
Question: 02
Answer: a
Question: 03
Answer: c
Question: 04
Answer: b
Question: 05
Answer: a, c
Question: 06
Answer: a
Question: 07
Answer: c
Question: 08
Answer: b, d
Question: 09
Answer: a
Question: 10
Answer: d

Note: For any error in CREST Certified Tester - Application (CCT APP) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (110 votes)