CREST CCRTM-SC 試験概要:
| 認定ベンダー: | CREST |
|---|---|
| 試験名: | CREST Certified Red Team Manager - Scenario |
| 試験番号: | CCRTM-SC |
| 受験料: | $850 USD |
| 試験時間: | 195分(試験時間180分 + 事前閲覧時間15分) |
| 認定の有効期間: | 3年間 |
| 合格点: | 非公開(各評価要素に基づく合格判定) |
| 対応言語: | 英語 |
| 出題数: | シナリオベースの評価(選択式問題の固定数なし) |
| 試験形式: | クローズドブック(資料持ち込み不可), インジェクト(状況の変化・追加課題)に基づく評価, 記述式シナリオ試験, 脅威インテリジェンスパックの提供あり |
| 関連資格: | CCRTM-MCLF — CREST Certified Red Team Manager - Multiple Choice & Long Form |
| 推奨トレーニング: | CREST認定トレーニングプロバイダー |
| 受験申し込み: | CREST公式登録 Pearson VUE 試験予約 |
| サンプル問題: | CREST CCRTM-SC サンプル問題 |
| 受験方法: | CREST試験センターまたはPearson VUE認定試験センターにて実施(現地監督付き記述式試験) |
| 前提条件: | 必須の前提資格はありませんが、CRESTは規制環境下でレッドチームエンゲージメントを主導した実務経験を推奨しています。 |
| 公式シラバスのURL: | https://www.crest-approved.org/skills-certifications-careers/crest-certified-red-team-manager/ |
CREST CCRTM-SC 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: レッドチームエンゲージメント管理 | - シナリオベースのエンゲージメント計画
|
CREST Certified Red Team Manager - Scenario 認定 CCRTM-SC 試験問題:
問題 #1
Background: You lead the threat intelligence workstream for an intelligence-led engagement against Thornbury Energy Supply, a mid-sized UK energy retailer voluntarily commissioning STAR-FS-aligned testing. Two of your open-source intelligence sources - a well-regarded commercial threat intelligence feed (historically rated highly reliable) and a smaller, independent security researcher's blog (previously unrated by your team, but sometimes cited by others in the industry) - offer conflicting characterisations of the most plausible threat actor. The commercial feed assesses that Thornbury's sector is currently most targeted by a financially motivated group using commodity ransomware delivered via exposed RDP and unpatched VPN appliances. The independent blog, in a recent post, claims - citing an anonymous source it does not name - that a specific, more sophisticated actor group is "actively targeting UK mid-sized energy retailers specifically" using a novel technique involving compromised smart-metering data platforms, though no other source you can find corroborates this specific claim.
Your junior analyst is enthusiastic about the independent blog's claim, arguing "it's much more interesting and specific to energy, and the smart-metering angle would make for a really compelling, novel scenario for the client." Separately, the engagement's fixed timeline only allows for one primary scenario to be developed in the time available.
Question: Explain how you would assess and reconcile these conflicting sources, and justify which scenario direction you would ultimately recommend, addressing the analytical principles involved.
問題 #2
Background: You are scoping an engagement for Ashcombe Retail Bank, a mid-sized UK bank preparing for its first CBEST engagement. During the scoping workshop, the Head of Digital Channels strongly advocates for an objectives-based ("flag") approach, proposing a single objective: "achieve unauthorised funds transfer capability in the core payments system." The Head of Operational Resilience, in the same meeting, separately advocates for a crown-jewels (asset-based) approach explicitly listing seven named critical systems that must each be individually assessed, arguing the board specifically wants to see coverage confirmation against each one for their operational resilience self-assessment.
Both stakeholders are Control Group members, and neither is aware the other has a different underlying preference until this workshop, where the disagreement becomes evident in real time. The engagement's resourcing (agreed with the Bank of England as broadly appropriate for a first CBEST engagement of this bank's size) is not large enough to comfortably deliver a deep, patient, objectives-based campaign against one target AND a full individual assessment of all seven named systems within the available testing window.
Question: As the Red Team Manager facilitating this scoping workshop, how would you help the Control Group resolve this disagreement, and what would you recommend? Explain your reasoning.
解説:
| 問題 #1 正解: 会員のみ閲覧可能 | 問題 #2 正解: 会員のみ閲覧可能 |














0 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
