CREST CCRTM-SC 시험 개요:
| 인증 벤더: | CREST |
|---|---|
| 시험명: | CREST Certified Red Team Manager - Scenario |
| 시험 번호: | CCRTM-SC |
| 합격 점수: | 시나리오 영역 120점 만점 중 최소 84점(70%) 이상 |
| 자격증 유효 기간: | 응시일로부터 3년 |
| 지원 언어: | 영어 |
| 관련 자격증: | CREST Certified Red Team Manager (CCRTM) |
| 응시료: | £800 + VAT |
| 시험 시간: | 180분 |
| 실제 시험 문항 수: | 시나리오 문제 1개 |
| 시험 형식: | 시나리오 문제, 서술형 시나리오 |
| 샘플 문제: | CREST CCRTM-SC 샘플 문제 |
| 응시 방법: | 전 세계 지정된 Pearson VUE 시험 센터에서 실시되는 대면 컴퓨터 기반 시험입니다. Scenario 영역은 서적을 참조할 수 없는 폐쇄형(Closed-book) 서술형 시험입니다. 응시자는 3시간의 Scenario 시험 개시 전 15분의 추가 검토 시간을 부여받습니다. |
| 전제 조건: | CREST는 CCRTM 시험에 대한 별도의 사전 선수 시험을 명시하지 않으나, CCRTM 자격증 취득을 위해서는 Multiple Choice & Long Form 시험과 Scenario 시험을 모두 통과해야 합니다. |
| 공식 요강 URL: | https://www.crest-approved.org/ccrtm-faqs/ |
CREST CCRTM-SC 시험 요강 주제:
| 섹션 | 목표 |
|---|---|
| 주제 1: 공격 방법론, 주요 단계 및 공통 프레임워크 | - 권한 상승 기법 및 위험 - 물리적 접근 통제 우회 및 위험 - 공격 방법론 프레임워크 - 측면 이동(Lateral Movement) 기법 및 위험 - 하이브리드 환경 테스트 및 위험 - 최초 침투(Initial Access) 기법 및 위험 - 클라우드 환경 테스트 및 위험 - 지속성(Persistence) 유지 기법 및 위험 |
| 주제 2: 위협 인텔리전스 | - 위협 모델 고려사항 - 능동적 방법론 대 수동적 방법론의 장점 - 위협 인텔리전스 출처 - 위협 인텔리전스 출처의 법적·윤리적 고려사항 |
| 주제 3: Dropper/Implant 설계, 안전성 및 Secure Coding | - Implant 통제 - Implant 핵심 기능 및 위험 - Implant Dropper의 기능 및 위험 - 인프라 통제 - 지속성(Persistent) vs 반지속성(Semi-Persistent) Implant 설계 및 위험 - 안전한 데이터 처리 - 암호화(Encryption) vs 인코딩(Encoding) |
| 주제 4: 프로젝트 관리, 거버넌스 및 감독 | - 침해 사고 관리 대응 - 이해관계자 관리 및 프로젝트 무결성 - Red Team 프로젝트 수행 단계 - 커뮤니케이션 계획 - 통제 그룹의 역할 및 책임 |
| 주제 5: 공격 관리의 법적·윤리적·도덕적 측면 | - 데이터 처리 관련 법률 - 윤리적 테스트 고려사항 - 개인정보 보호 관련 법률 - 의도치 않은 타겟팅 및 부수적 피해 타겟팅 - 컴퓨터 범죄/사이버 남용 및 오용 관련 법률 - 기타 관련 법률 및 계약 정보 |
| 주제 6: 핵심 개념 | - 탐지 및 대응 평가 - 용어 정의 - Red Team 프레임워크 - 공격 경로 매핑 및 공격 경로 시뮬레이션 - Red Team, Purple Team 테스트, 침투 테스트 |
| 주제 7: 수행 규칙, 비상 대책 및 시나리오 시뮬레이션 | - 비상 대책 / 고객 지원 - 시나리오 유형 - 수행 규칙(Rules of Engagement) - 테스트 계획 |
| 주제 8: 기획 및 범위 지정 | - 프로젝트 이해관계자 - 요구사항 분석(범위 지정) |
| 주제 9: 위험 관리, 보고 및 커뮤니케이션 | - 프로젝트 위험 관리 - 위험의 명확한 전달 및 설명 - 국제 공인 표준 및 프레임워크 - 위험 관리 용어집 |
최신 CREST Certified CCRTM-SC 무료샘플문제
문제 #1
Background: You manage a team of eight consultants delivering three concurrent engagements: a 10-week CBEST engagement for a bank (in week 4), an 8-week STAR-FS engagement for a mid-sized insurer (in week 2), and a shorter, 3-week commercial red team engagement for a technology company (in week 1). Your most experienced Active Directory and Windows domain specialist, who was central to the technical plan for the CBEST engagement's most complex planned attack path, unexpectedly resigns with immediate effect for personal reasons in week 4 of the CBEST engagement. No documented deputy or succession plan exists for this specific role on this engagement. At the same time, two junior consultants on the insurer engagement have separately, informally mentioned to their team lead that they are feeling overwhelmed by the pace of concurrent workstreams.
The CBEST Control Group is expecting a status update in three days, and the originally planned technical approach for the remaining weeks depended heavily on the departed specialist's specific expertise.
Question: As Red Team Manager, set out the immediate actions you would take in the next 72 hours, and explain the underlying resourcing and risk management principles that should have been (and should now be) applied.
문제 #2
Background: You are the Red Team Manager responsible for delivering a CBEST engagement for Solenne Retail Bank plc, a UK bank designated by the Bank of England as core to financial stability. Your firm has been engaged as the accredited penetration testing provider; a separate accredited firm is delivering the threat intelligence workstream. Six weeks into the Threat Intelligence phase, the CTI provider's draft Targeting Intelligence Report identifies a financially motivated, moderately sophisticated organised crime group as the most plausible threat actor, based on strong evidence of similar groups actively targeting three comparable UK retail banks in the preceding twelve months using business email compromise, credential phishing, and abuse of a common payment-processing middleware product that Solenne also uses.
Two days before the Targeting Intelligence Report is due to be finalised, Solenne's Group CISO - who chairs the Control Group - contacts you directly (bypassing the CTI provider) and states that the board would "much prefer" the scenario to focus on a sophisticated nation-state actor, because the board considers this "more prestigious" and because a recent internal strategy paper positioned Solenne as being concerned primarily with nation-state risk. The CISO asks you, as the penetration testing provider, to simply proceed with planning a nation-state-style scenario regardless of what the CTI provider's report concludes, to save time given the tight testing window ahead of a fixed year-end reporting deadline.
Separately, your own delivery team flags that the payment-processing middleware identified by the CTI provider as a plausible attack path is also used by a separate, unrelated business unit of Solenne's parent group that was explicitly excluded from the agreed CBEST scope.
Question: As Red Team Manager, how should you respond to (a) the Group CISO's request to disregard the CTI provider's evidence-based conclusion in favour of a nation-state scenario, and (b) the discovery that the identified plausible attack path touches an excluded business unit? Explain the governance principles underpinning your response and the specific steps you would take.
질문과 대답:
| 문제 #1 정답: 회원만 볼 수 있음 | 문제 #2 정답: 회원만 볼 수 있음 |














0 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
