Posts

CREST Practitioner Intrusion Analyst: CPIA Exam Information

Image
  2. EXAMINATION DETAILS (CPIA)  2.1 Format The CREST Practitioner Intrusion Analyst examination is delivered at Pearson Vue Centres. Please visit www.pearsonvue.com and follow the on-screen instructions to schedule your chosen examination. Note the logistical requirements for exams conducted at a Pearson Vue centre are defined by Pearson Vue and candidates must ensure they adhere to all the necessary requirements as listed on their website. CREST candidates are not exempt from any of the standard requirements. The CPIA examination comprises one hundred and twenty (120) multiple choice questions, all of which the candidate must complete Details of the areas covered can be found in the Syllabus document.  2.2 Timings The examination lasts 2 hours. Note that the permitted maximum session time at Pearson Vue is 2.5 hours in total, allowing time to read the Code of Conduct and also to provide feedback following the examination.  2.3 Open Book/Closed Book The ex...

F12 Behavioural Analysis

 Use of common tools to identify patterns of behaviour Aspects of command and control Infection vectors and persistence mechanisms  

F11 Binary Obfuscation

Packers and Executable Encryption  Techniques to restore packed executables  Rebuilding executable content from memory  Virtual machine instruction sets (e.g. PCode)

F10 Malware Reporting

 Signature identification    Cleanup of malware   Infection vectors    Footprint

F9 Hiding Techniques

Common techniques for process injection Rootkit techniques for hiding files and other system resources including: SSDT patching  Filter drivers Process list manipulation   

F8 Windows Executable File Formats

Standard windows executable formats (e.g. PE, EXE, COM)  Extracting important information in executable files

F7 Processor Architectures

Intel x86/x64 instruction set  Virtual Memory Implementation  Virtualization Technology