CREST CCRTM-SC 考試概覽:
| 認證廠商: | CREST |
|---|---|
| 考試名稱: | CREST Certified Red Team Manager - Scenario |
| 考試代碼: | CCRTM-SC |
| 相關認證: | CCRTM-MCLF — CREST Certified Red Team Manager - Multiple Choice & Long Form |
| 及格分數: | 未公開揭露(採計分項目綜合評估) |
| 證照有效期限: | 3 年 |
| 考試費用: | $850 USD |
| 實際考試題數: | 情境式考核(無固定單選題數量) |
| 支援語言: | 英文 |
| 考試時間: | 195(180 分鐘考試 + 15 分鐘閱讀時間) |
| 考試形式: | 情境筆試, 提供威脅情報包 (Threat Intelligence Pack), 動態注入事件 (Inject) 考核, 閉卷考試 |
| 推薦課程: | CREST 認證培訓機構 |
| 考試報名: | CREST 官方註冊 Pearson VUE 預約考試 |
| 範例考題: | CREST CCRTM-SC 範例考題 |
| 考試方式: | 於 CREST 考試中心 / Pearson VUE 授權考試中心進行(現場監考筆試) |
| 必備條件: | 無強制性先修考試;但 CREST 建議具備在受監管環境中領導紅隊演練的實務經驗。 |
| 官方大綱網址: | https://www.crest-approved.org/skills-certifications-careers/crest-certified-red-team-manager/ |
CREST CCRTM-SC 考試大綱主題:
| 章節 | 目標 |
|---|---|
| 主題 1: 紅隊演練專案管理 | - 基於情境的演練規劃
|
最新的 CREST Certified CCRTM-SC 免費考試真題:
問題 #1
Background: You manage a red team engagement for Priorswood Legal Services Group, a firm that (unusually for your typical financial-sector client base) is itself a law firm with several regulated legal practice areas. During the engagement's OSINT and social engineering planning phase, your team compiles detailed public-source profiles of several named partners and senior associates to support a spear-phishing pretext, including publicly available information about their professional specialisms, recent case involvements mentioned in public court records and law firm marketing materials, and social media activity.
Priorswood's General Counsel (who, unusually, is also acting as a Control Group member for this engagement) raises a specific concern during a status call: some of the case involvement information your team has gathered, while technically drawn from public sources, relates to ongoing client matters that are subject to legal professional privilege from the perspective of Priorswood's own clients, and she is concerned that even referencing this information in your phishing pretexts or internal working documents could create a paper trail that "looks uncomfortably close to us handling privileged client-matter information carelessly, even though it's just OSINT." Question: Assess the General Counsel's concern, and explain how your team should handle OSINT collection and use in this specific engagement context, including any changes you would make to your standard approach.
問題 #2
Background: You are the Red Team Manager responsible for delivering a CBEST engagement for Solenne Retail Bank plc, a UK bank designated by the Bank of England as core to financial stability. Your firm has been engaged as the accredited penetration testing provider; a separate accredited firm is delivering the threat intelligence workstream. Six weeks into the Threat Intelligence phase, the CTI provider's draft Targeting Intelligence Report identifies a financially motivated, moderately sophisticated organised crime group as the most plausible threat actor, based on strong evidence of similar groups actively targeting three comparable UK retail banks in the preceding twelve months using business email compromise, credential phishing, and abuse of a common payment-processing middleware product that Solenne also uses.
Two days before the Targeting Intelligence Report is due to be finalised, Solenne's Group CISO - who chairs the Control Group - contacts you directly (bypassing the CTI provider) and states that the board would "much prefer" the scenario to focus on a sophisticated nation-state actor, because the board considers this "more prestigious" and because a recent internal strategy paper positioned Solenne as being concerned primarily with nation-state risk. The CISO asks you, as the penetration testing provider, to simply proceed with planning a nation-state-style scenario regardless of what the CTI provider's report concludes, to save time given the tight testing window ahead of a fixed year-end reporting deadline.
Separately, your own delivery team flags that the payment-processing middleware identified by the CTI provider as a plausible attack path is also used by a separate, unrelated business unit of Solenne's parent group that was explicitly excluded from the agreed CBEST scope.
Question: As Red Team Manager, how should you respond to (a) the Group CISO's request to disregard the CTI provider's evidence-based conclusion in favour of a nation-state scenario, and (b) the discovery that the identified plausible attack path touches an excluded business unit? Explain the governance principles underpinning your response and the specific steps you would take.
問題與答案:
| 問題 #1 答案: 僅成員可見 | 問題 #2 答案: 僅成員可見 |

下載最新試用版
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。


0位客戶反饋


