CREST CCRTM-SC 試験概要:
| 認定ベンダー: | CREST |
|---|---|
| 試験名: | CREST Certified Red Team Manager - シナリオ |
| 試験番号: | CCRTM-SC |
| 合格点: | シナリオ部門の合格点はCRESTにより公開されていません |
| 試験時間: | 195 分 |
| 受験料: | £800 + VAT |
| 関連資格: | CREST Certified Red Team Manager (CCRTM) |
| 対応言語: | 英語 |
| 出題数: | 公開されていません |
| 認定の有効期間: | 受験日から3年間 |
| 試験形式: | シナリオベースの設問, 記述式シナリオ |
| 受験申し込み: | Pearson VUE CREST認定資格の価格および予約 |
| サンプル問題: | CREST CCRTM-SC サンプル問題 |
| 受験方法: | Pearson VUEテストセンターにて実施されます。CCRTMシナリオは記述式シナリオ試験です。試験時間は3時間で、試験開始前に15分間の読解時間が設けられています。 |
| 前提条件: | CRESTはCCRTM試験に対して前提条件を定めていません。CCRTM資格は、「多肢選択式・長文記述式」と「シナリオ」の2つの部門で構成されており、それぞれ個別に予約する必要があります。両部門に合格することが求められます。 |
| 公式シラバスのURL: | https://www.crest-approved.org/ccrtm-faqs/ |
CREST CCRTM-SC 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: 脅威インテリジェンス | - 脅威インテリジェンスの情報源 - 脅威インテリジェンス情報源に関する法的・倫理的考慮事項 - 能動的手法と受動的手法の利点 - 脅威モデル |
| トピック 2: リスク管理、報告およびコミュニケーション | - エンゲージメントリスク管理 - リスクの明確化 - リスク管理用語集 - 国際的に認められた標準とフレームワーク |
| トピック 3: 主要概念 | - 検出・対応評価 - 用語 - レッドチーム、パープルチームテストおよびペネトレーションテスト - レッドチームフレームワーク - 攻撃パスマッピングおよび攻撃パスシミュレーション |
| トピック 4: 計画とスコーピング | - 要件分析とスコーピング - エンゲージメントのステークホルダー |
| トピック 5: 攻撃手法、主要段階および一般的なフレームワーク | - 物理的アクセス制御の回避とリスク - クラウド環境テストとリスク - 権限昇格技術とリスク - 初期アクセス技術とリスク - ハイブリッド環境テストとリスク - ラテラルムーブメント技術とリスク - 永続化技術とリスク - 攻撃手法フレームワーク |
| トピック 6: ドロッパー・インプラント設計、安全性およびセキュアコーディング | - 永続型と半永続型インプラント設計とリスク - インプラント制御 - 暗号化とエンコーディング - インプラントのコア機能とリスク - セキュアなデータ取り扱い - インフラストラクチャ制御 - インプラントドロッパーの機能とリスク |
| トピック 7: 攻撃管理における法的・倫理的・道徳的側面 | - 倫理的テストに関する考慮事項 - その他の関連法律および契約情報 - データ取り扱いに関する法律 - プライバシーに関する法律 - コンピュータ犯罪、サイバー不正使用および悪用に関する法律 - 意図しない標的設定および付随的標的設定 |
| トピック 8: プロジェクト管理、ガバナンスおよび監督 | - コントロールグループの役割と責任 - レッドチームエンゲージメントの各段階 - ステークホルダー管理とエンゲージメントの完全性 - インシデント管理対応 - コミュニケーション計画 |
| トピック 9: 交戦規則、緊急時対応およびシナリオシミュレーション | - 緊急時対応とクライアント支援 - テスト計画 - シナリオの種類 - 交戦規則 |
CREST Certified Red Team Manager - Scenario 認定 CCRTM-SC 試験問題:
問題 #1
Background: You manage a team of eight consultants delivering three concurrent engagements: a 10-week CBEST engagement for a bank (in week 4), an 8-week STAR-FS engagement for a mid-sized insurer (in week 2), and a shorter, 3-week commercial red team engagement for a technology company (in week 1). Your most experienced Active Directory and Windows domain specialist, who was central to the technical plan for the CBEST engagement's most complex planned attack path, unexpectedly resigns with immediate effect for personal reasons in week 4 of the CBEST engagement. No documented deputy or succession plan exists for this specific role on this engagement. At the same time, two junior consultants on the insurer engagement have separately, informally mentioned to their team lead that they are feeling overwhelmed by the pace of concurrent workstreams.
The CBEST Control Group is expecting a status update in three days, and the originally planned technical approach for the remaining weeks depended heavily on the departed specialist's specific expertise.
Question: As Red Team Manager, set out the immediate actions you would take in the next 72 hours, and explain the underlying resourcing and risk management principles that should have been (and should now be) applied.
問題 #2
Background: You are the Control Team Lead's primary point of contact at the Red Team provider for a TIBER-EU engagement against Larchmont Insurance SE. In week 9 of the required 12-week active Red Team testing phase, your team achieves the agreed primary objective (demonstrating a realistic path to manipulating claims-payment data) far earlier than the original plan anticipated, and does so without being detected by the Blue Team at any point. Your lead tester messages you, enthusiastic, suggesting that since the objective is already achieved with three weeks of the mandated minimum window still remaining, the team should simply
"wrap up early, write the report now, and free up the team for other engagements," since "we've proven the point already and nothing important is likely to change in the remaining weeks." Separately, the Threat Intelligence Report identified a secondary, lower-probability but still plausible threat actor and attack path (targeting the SE entity's cross-border reinsurance data-sharing arrangements) that the original test plan had allocated the remaining weeks to explore, time permitting.
Question: Assess the lead tester's suggestion to conclude testing early, and explain what should actually happen with the remaining three weeks of the mandated testing window.
解説:
| 問題 #1 正解: 会員のみ閲覧可能 | 問題 #2 正解: 会員のみ閲覧可能 |














1 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
