CREST CCRTM-MCLF 考試概覽:
| 認證廠商: | CREST |
|---|---|
| 考試名稱: | CREST Certified Red Team Manager - Multiple Choice Long Form |
| 考試代碼: | CCRTM-MCLF |
| 實際考試題數: | 約 150 題選擇題 + 1 題長篇申論題 |
| 支援語言: | 英文 |
| 考試形式: | 長篇書面申論題, 選擇題 |
| 考試費用: | $850 USD |
| 考試時間: | 360 分鐘 |
| 相關認證: | CCRTS-P (CREST Certified Red Team Specialist - Practical) CCRTM-SC (CREST Certified Red Team Manager - Scenario) CCRTS-MCS (CREST Certified Red Team Specialist - Multiple Choice & Scenario) |
| 及格分數: | 選擇題:40 分(三分之二);申論題:80 分(三分之二)。兩個部分皆必須通過。 |
| 證照有效期限: | 未說明 |
| 推薦課程: | CREST 推薦培訓與準備資源 |
| 考試報名: | Pearson VUE 報名頁面 CREST 官方考試頁面 |
| 範例考題: | CREST CCRTM-MCLF 範例考題 |
| 考試方式: | 於 Pearson VUE 考試中心現場應試;閉卷考試。 |
| 必備條件: | 無強制性的先決條件;然而,應試者預期須具備廣泛的資訊安全知識,以及領導紅隊演練、滲透測試與模擬攻擊演練的經驗,優先考慮具備受監管環境下的相關經驗。 |
| 官方大綱網址: | https://www.crest-approved.org/skills-certifications-careers/crest-certified-red-team-manager/ |
CREST CCRTM-MCLF 考試大綱主題:
| 章節 | 目標 |
|---|---|
| 風險管理與報告 | - 演練期間的風險識別 - 向利害關係人提交具可操作性的報告 |
| 威脅情資與對手模擬 | - 將對手戰術對映至 MITRE ATT&CK 等框架 - 利用威脅情資設計攻擊情境 |
| 溝通與利害關係人互動 | - 向高層主管有效溝通發現事項 - 利害關係人期望管理 |
| 紅隊作業管理 | - 團隊協調與活動管理 - 演練進度監控與安全控管 |
| 治理、法律與合規性 | - 法律框架與授權流程 - 符合道德與合規的作業演練 |
| 紅隊演練規劃與策略 | - 定義目標、範圍與演練交戰規則 - 設計擬真的對抗情境 |
最新的 CREST Certified CCRTM-MCLF 免費考試真題:
問題 #1
Which of the following is the most accurate statement about the sequencing of Threat Intelligence and Red Team testing sub-phases within TIBER-EU's overall Testing phase?
A. Threat Intelligence work must complete first, since its output (the Targeted Threat Intelligence Report) forms the basis for the Red Team's scenario planning and execution
B. There is no distinction between these sub-phases
C. Red Team testing always precedes Threat Intelligence work
D. They occur simultaneously with no dependency
問題 #2
Which of the following is the most appropriate way to handle a request to include operational technology (OT) or industrial control systems (ICS) with potential life-safety implications within the scope of a red team engagement?
A. Apply significantly enhanced caution - carefully assess whether live testing is appropriate at all, consider safer alternative approaches (e.g., testing in a representative non-production environment, or a more limited, closely supervised assessment), and involve relevant engineering/safety stakeholders in the scoping decision
B. Allow testing to proceed without informing engineering or safety teams, to preserve realism
C. Include them in the same manner and with the same techniques as standard IT systems, with no special consideration
D. Automatically exclude all OT/ICS systems from every engagement with no further discussion
問題 #3
Which of the following best describes how governance of confidentiality should extend to the Red Team provider's own internal handling of client-sensitive material?
A. Internal governance of confidentiality is unnecessary as long as an NDA has been signed
B. The provider should apply its own robust internal governance - access controls, secure storage, need- to-know restriction, and staff confidentiality training - to protect client-sensitive material to a standard consistent with its contractual and professional obligations
C. Confidentiality governance is solely the client's responsibility to enforce within the provider's organisation
D. Confidentiality obligations apply only to the client, never to the provider's internal practices
問題 #4
What is GBEST generally understood to be?
A. A framework exclusively for testing physical building security
B. An intelligence-led testing framework adapted for UK government and public sector critical systems, conceptually modelled on the CBEST approach
C. A purely financial-sector scheme identical to CBEST
D. A private-sector marketing certification with no government involvement
問題 #5
Which of the following best describes the governance rationale for the internal Red Team provider organisation applying rigorous internal quality assurance review to a report before it is delivered to the client?
A. Internal QA review helps ensure findings are accurate, well-substantiated, clearly communicated, and consistent with agreed scope and professional standards before reaching the client, protecting both report quality and the provider's professional credibility
B. Internal QA review has no bearing on report quality or client trust
C. Internal QA review should only occur if specifically requested by the client
D. Internal QA review exists solely to inflate the reported number of findings
問題與答案:
| 問題 #1 答案: A | 問題 #2 答案: A | 問題 #3 答案: B | 問題 #4 答案: B | 問題 #5 答案: A |

下載最新試用版
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。


0位客戶反饋


