最新的CREST Certified Red Team Manager - Multiple Choice Long Form - CCRTM-MCLF免費考試真題

問題1
Why is segregation between the Control Group and the Blue Team (operational defenders) considered a core governance principle in intelligence-led testing?

正確答案: C
說明:(僅 VCESoft 成員可見)
問題2
Which of the following best describes why Rules of Engagement documents commonly include a defined document version history and change log?

正確答案: B
說明:(僅 VCESoft 成員可見)
問題3
Which of the following best describes the appropriate scope of who within the Red Team provider organisation must comply with the agreed RoE?

正確答案: C
說明:(僅 VCESoft 成員可見)
問題4
Which of the following best describes the purpose of explicitly documenting "assumptions and constraints" as part of a scoping document?

正確答案: B
說明:(僅 VCESoft 成員可見)
問題5
Which of the following best describes the governance value of holding regular (e.g., weekly) status update calls between the Red Team provider and the Control Group during a lengthy engagement?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題6
Which of the following best summarises the overall legal theme running through Rules of Engagement, written authorisation, data protection compliance, and insurance/indemnity provisions in red team engagements?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題7
Which of the following best explains why a red team's final report is often treated as a highly sensitive legal document, sometimes involving legal privilege considerations?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題8
What is the primary purpose of the purple team / replay exercise at TIBER-EU Closure?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題9
Overall, which statement best captures why rigorous threat intelligence and attack modelling capability is considered foundational to the credibility of the whole family of frameworks discussed in this document (CBEST, TIBER-EU, iCAST, and related schemes)?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題10
Which of the following best describes the management significance of maintaining appropriate professional indemnity and cyber liability insurance coverage levels as a red team practice's client base and engagement risk profile grows?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題11
Which statement best reflects how criminal liability risk under laws like the Computer Misuse Act typically differs between a properly authorised red team engagement and unauthorised "grey hat" testing of the same systems?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題12
Which of the following best describes the role of the independent Test Manager in TIBER-EU?

正確答案: C
說明:(僅 VCESoft 成員可見)