工作與課業夾擊之下,留給 CCRTM-SC 考試的準備時間總是不夠用?PDFExamDumps 把 CREST Certified Red Team Manager - Scenario 的精華濃縮成 20 道練習題,讓你用零碎時間也能高效率複習。
CREST CCRTM-SC 考試概覽:
| 認證廠商: | CREST |
|---|---|
| 考試名稱: | CREST Certified Red Team Manager - Scenario |
| 考試代碼: | CCRTM-SC |
| 考試時間: | 195 分鐘 |
| 相關認證: | CREST Certified Red Team Manager (CCRTM) |
| 實際考試題數: | 未公開 |
| 證照有效期限: | 自應考日起算 3 年 |
| 及格分數: | CREST 未公開情境考核部分的合格分數 |
| 考試費用: | £800 + VAT |
| 支援語言: | 英文 |
| 考試形式: | 情境筆試, 情境導向題 |
| 考試報名: | CREST 認證價格與報名預約 Pearson VUE |
| 範例考題: | ![]() |
| 考試方式: | 在 Pearson VUE 測試中心應考;CCRTM Scenario 為情境筆試。考試時間為 3 小時,考前另有 15 分鐘閱讀時間。 |
| 必備條件: | CREST 未針對 CCRTM 考試設定前置條件。CCRTM 資格認證包含兩個需分別預約的考科:選擇題與問答題 (Multiple Choice & Long Form) 以及情境考核 (Scenario)。應考人必須通過這兩個部分。 |
| 官方大綱網址: | https://www.crest-approved.org/ccrtm-faqs/ |
CREST CCRTM-SC 考試大綱主題:
| 章節 | 目標 |
|---|---|
| 威脅情報 | - 威脅模型 - 威脅情報來源 - 主動與被動方法論的優劣比較 - 威脅情報來源的法律與道德考量 |
| 核心概念 | - 攻擊路徑繪製與攻擊路徑模擬 - 偵測與回應評估 - 紅隊、紫隊測試與滲透測試 - 專業術語 - 紅隊演練架構 |
| Dropper / Implant 設計、安全性與安全程式碼撰寫 | - 安全資料處理 - 基礎架構控制措施 - Implant 控制措施 - 持續型與半持續型 Implant 設計與風險 - Implant Dropper 功能與風險 - 加密與編碼 (Encryption vs Encoding) - Implant 核心功能與風險 |
| 風險管理、報告與溝通 | - 演練專案風險管理 - 風險管理術語集 - 國際認可的標準與架構 - 風險論述與表達 |
| 交戰規則、應變措施與情境模擬 | - 情境類型 - 應變措施與客戶協調協助 - 交戰規則 (Rules of Engagement) - 測試計畫 |
| 攻擊方法論、關鍵階段與常用架構 | - 混合環境測試與風險 - 橫向移動 (Lateral Movement) 技術與風險 - 權限提升 (Privilege Escalation) 技術與風險 - 持續性控制 (Persistence) 技術與風險 - 初始存取 (Initial Access) 技術與風險 - 實體存取控制繞過技術與風險 - 攻擊方法論架構 - 雲端環境測試與風險 |
| 專案管理、治理與監督 | - 利益相關者管理與演練誠信 - 紅隊演練的各個階段 - 資安事件管理與回應 - 溝通計畫 - 控制小組 (Control Group) 的角色與職責 |
| 專案規劃與範圍界定 | - 專案利益相關者 - 需求分析與範圍界定 |
| 攻擊管理的法律、倫理與道德層面 | - 非預期與附帶影響的目標打擊 - 道德測試考量事項 - 電腦犯罪、網路濫用與誤用相關法規 - 資料處理相關法規 - 隱私相關法規 - 其他相關法規與合約資訊 |
CREST Certified Red Team Manager - Scenario 備考必讀問答
CCRTM-SC 是 CREST 原廠推出的認證考試,正式名稱為 CREST Certified Red Team Manager - Scenario,通過後即可取得 CREST Certified Red Team Manager (CCRTM) 認證,此認證屬於 Certified 級別。它與 CREST Certified Red Team Manager (CCRTM) 等認證彼此關聯,規劃進修路線時可以一併參考。準備這門考試時,PDFExamDumps 的 20 道 CCRTM-SC 練習題能幫你快速抓出命題重點。
官方公布的 CCRTM-SC 考試題量為 未公開,作答時間為 195 分鐘。想在時限內從容答完,建議練習時就養成節奏感:先快速瀏覽全卷、把題目分成「會」與「不確定」兩類,不確定的題目標記後先跳過,確保基本分入袋再回頭處理。考前用 PDFExamDumps 的桌面測試引擎做幾次全程計時模考,對時間分配的掌控會明顯進步。
CCRTM-SC 考試的及格門檻為 CREST 未公開情境考核部分的合格分數,官方報名費為 £800 + VAT。由於重考必須重新全額繳費,等於每多考一次就多一筆開銷,建議報名之前先用 PDFExamDumps 的 20 道模擬試題自我測驗,連續幾次都穩定超過及格線,再花這筆報名費才划算。
CREST 未針對 CCRTM 考試設定前置條件。CCRTM 資格認證包含兩個需分別預約的考科:選擇題與問答題 (Multiple Choice & Long Form) 以及情境考核 (Scenario)。應考人必須通過這兩個部分。
報考資格可能隨官方政策更新,動身報名前請以官方頁面公告為準:https://www.crest-approved.org/ccrtm-faqs/
以下是 CCRTM-SC 考試的官方報名管道:
考試方式:在 Pearson VUE 測試中心應考;CCRTM Scenario 為情境筆試。考試時間為 3 小時,考前另有 15 分鐘閱讀時間。。
原廠針對 CCRTM-SC 考試推薦了以下培訓:
上完課程建立觀念之後,別忘了用 PDFExamDumps 的 20 道 CCRTM-SC 練習題驗收學習成果,觀念加實戰才是完整的準備。
沒問題。PDFExamDumps 提供 CCRTM-SC 免費範例試題,先下載看看題目品質與解析深度,覺得合用再購買完整版,不用冒任何風險。購買之後 365 天內享有免費更新;一年期滿產品過期,若想延長更新服務,還能用 50% 的優惠價續購。
PDFExamDumps 設有「退款保證」:購買後 60 天內參加 CCRTM-SC 對應考試而未通過,可申請全額退費。申請時請在考後 2 天內備齊報名證明(准考證/enrollment slip)複印件與官方成績單 Score Report PDF,我們會在 7 天內處理完成;考生姓名必須與付款人姓名一致,購買後 3 天內即應考、已下載但未應考、免費資料及過期訂單不在適用範圍內。不想退款的話,也能改為免費換取兩個等值考試資料,原購產品的更新服務繼續保留。
至於交付,付款成功後系統一分鐘內就會把產品寄到你的電子郵件信箱,馬上就能下載使用;若超過 2 小時仍未收到,請聯絡客服處理。題庫不限制安裝的電腦數量,公司與家裡的電腦都能裝。
官方將 CCRTM-SC 考試範圍分為 9 個領域,先帶你看前三個:
- 交戰規則、應變措施與情境模擬
- 攻擊方法論、關鍵階段與常用架構
- Dropper / Implant 設計、安全性與安全程式碼撰寫
想知道每個領域底下的細項與完整配分,請直接查看上方的考試大綱區塊,此處不再贅述。
最新的 CREST Certified CCRTM-SC 免費考試真題:
問題 #1
Background: You manage a red team engagement for Brackenfell Retail Group under an RoE that explicitly permits "controlled, non-destructive proof-of-concept payload execution to demonstrate exploitation of identified vulnerabilities" but explicitly prohibits "any activity resulting in encryption, deletion, or exfiltration of production data." During week 5, your team successfully exploits a vulnerability in an internal file server and, to demonstrate impact, executes a small proof-of-concept script that creates a single new, clearly labelled test file ("REDTEAM-POC-DO-NOT-DELETE.txt") containing only benign placeholder text, then takes a screenshot as evidence, and immediately deletes the test file it created.
A junior tester on the team, reviewing this activity in the daily standup, raises a question: "Doesn't creating and then deleting a file, even one we created ourselves, technically fall under 'deletion... of production data,' since it was on a production file server?" Separately, that same day, a different, more senior tester proposes going further on a different system: rather than just creating a placeholder file, they suggest locating one genuinely low-value, clearly non-critical existing file (e.g., an old, unused template document) already present on a production file share, and temporarily renaming it (not deleting it) to demonstrate write-access impact more "authentically," planning to rename it back immediately afterward.
Question: Assess whether the actions already taken (creating and deleting the labelled test file) were consistent with the RoE, and explain how you should respond to the senior tester's proposal to rename an existing production file. What broader RoE interpretation principle does this scenario illustrate?
問題 #2
Background: You are the Red Team Manager for a 12-week TIBER-EU-aligned engagement. In week 7, your firm wins a large, unrelated new contract that your firm's leadership is keen to staff quickly, and you are asked by your own Practice Director to release your firm's second-most-senior consultant on the current engagement
- who has been leading the more technically complex of two parallel attack paths - to begin work on the new contract "part-time, starting Monday, just two days a week for now," while remaining nominally on the TIBER-EU engagement the other three days.
The consultant in question tells you privately that they do not believe they can properly context-switch between a slow-paced, patient, intelligence-led campaign requiring sustained situational awareness of a live target environment, and a fast-moving new client kickoff, without a real risk of errors or missed detail on one or both engagements. Separately, the client's Control Team Lead has no visibility yet of this proposed change and has previously stressed how much they value consistency of personnel on such a sensitive, lengthy engagement.
Question: As Red Team Manager, how would you handle this internal resourcing request from your own firm's leadership, balancing your firm's commercial interests against your professional obligations on the current TIBER-EU engagement? Explain your reasoning and the steps you would take.
問題與答案:
| 問題 #1 答案: 僅成員可見 | 問題 #2 答案: 僅成員可見 |




0位客戶反饋
