GoShiken は CCRTM-SC 試験「CREST Certified Red Team Manager - Scenario」のサンプル問題を無料で提供しています。購入する前、弊社の模擬試験画面や問題のクオリティー、使いやすさを事前に体験できます。
CREST Certified Red Team Manager - Scenario: CCRTM-SC 試験
「CREST Certified Red Team Manager - Scenario」、CCRTM-SC試験であります、CREST認定でございます。 最適な問題と解答をまとめられて、GoShiken はお客様のCCRTM-SC試験に計 20 問をまとめてご用意いたしました。CCRTM-SC試験の集結内容には、CREST Certified認定にあるエリアとカテゴリの全てをカバーしており、お客様の CREST Certified Red Team Manager - Scenario 試験認定合格の準備を手助けをお届けします。
リアルなCCRTM-SCテストエンジン
弊社のCREST Certified Red Team Manager - Scenario受験資料はお客様がCREST CCRTM-SC試験を受けるために必要なすべてのものが含まれています。詳細はCREST Certified Red Team Manager - Scenario認証専門家側が研究して制作されて、彼らは業界の経験を利用して正確で論理的な制品を改良され続けています。
品質と価値のあるCCRTM-SC試験問題
GoShiken練習試験CREST CCRTM-SCは認定された対象分野の専門家と公開された作成者のみを招いて、最高水準の技術的精度で作成されています。
CCRTM-SC試験合格を100%返金保証
お客様がもしGoShikenのテストエンジンを使って CCRTM-SC 試験「CREST Certified Red Team Manager - Scenario」に不合格されました場合、弊社はお客様に購入金額を全額返金致します。
- CCRTM-SC 試験に関する広範囲的な問題と解答
- CCRTM-SC 試験問題集は事前使用できる
- 問題は業界の専門家によって調査されて、ほぼ100%正解率の検証済みの回答
- CCRTM-SC 試験問題集は定期的に更新されます
- 本番試験を基づいてまとめられた CCRTM-SC 問題集
- こちらの問題集は販売される前に複数回シミュレーション済み
- GoShiken で購入すると決める前に、無料で CCRTM-SC 試験問題集のサンプルを試せます
365日無料アップデート
購入日から365日無料アップデートをご利用いただけます。365日後、CCRTM-SC問題集更新版がほしく続けて50%の割引を与えれます。
インスタントダウンロード
お支払い後、弊社のシステムは、1分以内に購入したCCRTM-SC問題集をあなたのメールボックスにお送りします。 2時間以内に届かない場合に、お問い合わせください。
100%返金保証
購入後60日以内に、CCRTM-SC試験に合格しなかった場合は、全額返金します。 そして、無料で他の試験問題集を入手できます。
CREST Certified Red Team Manager - Scenarioは出題範囲が広く、独学だけでは論点を網羅しにくい試験です。GoShikenのCCRTM-SC問題集は本番の出題傾向を踏まえた20問で構成されており、苦手分野を効率的に洗い出せます。
CREST CCRTM-SC 試験概要:
| 認定ベンダー: | CREST |
|---|---|
| 試験名: | CREST Certified Red Team Manager - Scenario |
| 試験番号: | CCRTM-SC |
| 試験時間: | 195分(試験時間180分 + 事前閲覧時間15分) |
| 出題数: | シナリオベースの評価(選択式問題の固定数なし) |
| 試験形式: | インジェクト(状況の変化・追加課題)に基づく評価, 記述式シナリオ試験, クローズドブック(資料持ち込み不可), 脅威インテリジェンスパックの提供あり |
| 認定の有効期間: | 3年間 |
| 対応言語: | 英語 |
| 受験料: | $850 USD |
| 合格点: | 非公開(各評価要素に基づく合格判定) |
| 関連資格: | CCRTM-MCLF — CREST Certified Red Team Manager - Multiple Choice & Long Form |
| 推奨トレーニング: | CREST認定トレーニングプロバイダー |
| 受験申し込み: | Pearson VUE 試験予約 CREST公式登録 |
| サンプル問題: | CREST CCRTM-SC サンプル問題 |
| 受験方法: | CREST試験センターまたはPearson VUE認定試験センターにて実施(現地監督付き記述式試験) |
| 前提条件: | 必須の前提資格はありませんが、CRESTは規制環境下でレッドチームエンゲージメントを主導した実務経験を推奨しています。 |
| 公式シラバスのURL: | https://www.crest-approved.org/skills-certifications-careers/crest-certified-red-team-manager/ |
CREST CCRTM-SC 試験シラバストピック:
| セクション | 目標 |
|---|---|
| レッドチームエンゲージメント管理 | - シナリオインジェクトへの対応
|
CCRTM-SC受験者からよく寄せられる質問
CCRTM-SC(CREST Certified Red Team Manager - Scenario)は、CRESTが提供する認定試験で、合格すると「CREST Certified Red Team Manager」の認定を取得できます。この認定はマネージャー / 上級レベルに位置づけられています。関連する認定にはCCRTM-MCLF — CREST Certified Red Team Manager - Multiple Choice & Long Formなどがあり、あわせて取得を目指す方も少なくありません。出題範囲の詳細は、このページの試験情報とGoShikenの練習問題でご確認いただけます。
CCRTM-SC試験の出題数はシナリオベースの評価(選択式問題の固定数なし)、試験時間は195分(試験時間180分 + 事前閲覧時間15分)です。問題数から逆算すると1問にかけられる時間は限られるため、知識を問う問題は即答し、シナリオ問題に時間を残すペース配分を意識しましょう。見直しの時間を確保するためにも、GoShikenのテストエンジンで本番と同じ制限時間の模擬試験を繰り返し、時間切れを防ぐ感覚をつかんでおくことをおすすめします。
CCRTM-SC試験の合格点は非公開(各評価要素に基づく合格判定)、受験料は$850 USDです。不合格となった場合、再受験には改めて全額の受験料が必要になります。金銭的な負担を増やさないためにも、受験前にGoShikenの20問の練習問題で自己採点を行い、安定して合格点を上回れる状態になってから本番に臨みましょう。
CCRTM-SC試験の受験条件は次のとおりです。必須の前提資格はありませんが、CRESTは規制環境下でレッドチームエンゲージメントを主導した実務経験を推奨しています。 受験条件は変更される場合があるため、最新情報は公式の試験案内ページで必ずご確認ください。
CCRTM-SC試験は、以下の窓口からお申し込みいただけます。
受験方式はCREST試験センターまたはPearson VUE認定試験センターにて実施(現地監督付き記述式試験)となっています。申し込み手順や受験日の詳細は、各窓口の案内をご確認ください。
CRESTは、CCRTM-SC試験の対策として次の公式トレーニングを推奨しています。
公式トレーニングで基礎を固めたうえで、GoShikenの20問の練習問題でアウトプットを重ねると、知識の定着を効率的に確認できます。
はい、GoShikenではCCRTM-SC対策の無料サンプル(PDFデモ)をご用意しています。実際の問題形式や解答の質をご確認いただいてからご購入いただけるため安心です。また、ご購入後は365日間、最新版への無料更新をご利用いただけます。365日を過ぎた後も更新サービスを50%割引で継続できますので、長期間にわたって最新の出題傾向に対応した教材をご活用いただけます。
GoShikenでは返金保証をご用意しています。ご購入後60日以内に対応する試験を受験し、残念ながら不合格となった場合は、受験票の写しと公式スコアレポート(Score Report)のPDFを試験後2日以内にご提出いただくことで、7日以内に全額を返金いたします。ただし、購入後3日以内の受験(学習期間が短すぎるため)、ダウンロードのみで未受験の場合、無料資料および期限切れのご注文は対象外です。また、受験者名とお支払い者名が一致している必要があります。返金の代わりに製品交換をご希望の場合は、同等の試験対策資料2点を無料でご提供し、ご購入済み製品の更新サービスもそのままご利用いただけます。納品は、お支払い完了後すぐにダウンロードできるほか、1分以内にご登録のメールアドレスへもお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールするパソコンの台数に制限はありませんので、ご自宅と職場など複数の環境で学習を進められます。
CCRTM-SC試験の出題範囲は、全部で1つの分野で構成されています。主な分野としては、「レッドチームエンゲージメント管理」などが挙げられます。各分野に含まれる具体的なトピックは、このページ上部の出題範囲に一覧で掲載していますので、学習計画を立てる際にご活用ください。
CREST Certified Red Team Manager - Scenario 認定 CCRTM-SC 試験問題:
Background: You are delivering an iCAST engagement for Silverpeak Bank, a Hong Kong Authorized Institution assessed as requiring Advanced maturity under C-RAF. During the Threat Intelligence phase, the accredited CTI provider identifies that Silverpeak's core banking platform runs partly on infrastructure within a shared data centre facility also used by two other, unrelated Authorized Institutions, with all three banks' racks physically located in adjacent, separately locked cages within the same facility, managed day-to-day by the data centre operator's own staff.
Silverpeak's internal Control Group is enthusiastic about a comprehensive test and asks whether the physical social engineering component of the engagement can include an attempt to gain unauthorised entry to the data centre facility itself, "to really test whether someone could walk in and get physical access to our servers." Separately, a member of your Red Team raises an informal concern that Hong Kong's specific legal position on authorised physical penetration testing "might be different from what we're used to on UK-only engagements" but nobody on the team has actually verified this for the current engagement.
Question: Explain how you would handle (a) the request to physically test entry to the shared data centre facility, and (b) the team member's informal legal concern, before this element of the engagement proceeds.
See The answer in Explanation part below.
Explanation:
Step 1 - Recognise the shared-facility authorisation problem. The data centre facility itself, and the general access points, common areas, and physical security controls governing entry to the building, are owned and operated by the data centre operator - a separate legal entity - not by Silverpeak. Silverpeak's authorisation can validly cover its own locked cage and the equipment within it, but it cannot validly authorise a physical intrusion attempt against the building's general access controls, which are the data centre operator's own infrastructure and responsibility, exactly analogous to the cloud/SaaS/telecommunications-provider authorisation-boundary issue addressed elsewhere in this syllabus, now applied to a physical rather than purely technical context.
Step 2 - Recognise the additional multi-tenant risk dimension. Beyond the pure authorisation question, a physical intrusion attempt against the shared facility risks affecting or alarming the other two unrelated Authorized Institutions whose cages are in immediate physical proximity - for example, if the attempt triggers a wider facility security response, lockdown, or law enforcement involvement affecting the whole building, not just Silverpeak's area. This mirrors the "shared multi-tenant environment" risk principle covered elsewhere in this syllabus regarding cloud infrastructure, now applied physically, and materially raises the stakes of proceeding without the operator's explicit involvement.
Step 3 - Do not proceed with the physical facility-entry component as currently framed. Given Steps 1 and
2, this specific element should not proceed on the basis of Silverpeak's authorisation alone. The professionally correct response to the Control Group is to explain clearly why their own authorisation cannot legally or safely extend to testing the shared building's general access controls, however enthusiastic they are about a comprehensive test.
Step 4 - Identify legitimate alternative approaches. Rather than simply declining outright, you should discuss constructive alternatives with the Control Group: (i) engaging the data centre operator directly to seek their explicit, separate consent for a properly scoped and coordinated physical test of the building's general access controls (which, if obtained, would need to be documented and would still require care given the other tenants' interests, potentially requiring their awareness or at least the operator's confirmation that testing is compatible with its own obligations to other tenants); (ii) narrowing the physical testing component to elements genuinely within Silverpeak's own control, such as testing access controls on Silverpeak's own locked cage itself (e.g., attempting to gain entry to the cage assuming a tester has already reached the general shared area through legitimate means, or testing whether Silverpeak's own escort/visitor procedures are followed by data centre staff who do have authorised access) - carefully scoped to avoid implicating the operator's own general building security; or (iii) excluding physical facility testing from this engagement and instead documenting physical access risk at the shared facility as a topic for Silverpeak's own vendor/facilities risk management and direct conversation with the data centre operator outside the iCAST engagement itself.
Step 5 - Address the legal-position concern rigorously, not informally. The team member's instinct that Hong Kong's legal position may differ from a "UK-only" assumption is exactly correct as a concern, and it should not be left informally unresolved. Consistent with the syllabus principle on jurisdiction-specific legal risk, your firm should not proceed with any physical social engineering element in Hong Kong based on assumptions carried over from UK engagements. This requires confirming (through your firm's own established Hong Kong legal understanding, given this is an iCAST-accredited engagement where such understanding should already exist, or through specific local legal advice if any doubt remains) the local legal position on trespass and physical intrusion testing, and ensuring the authorisation and RoE documentation for this specific engagement explicitly and correctly reflect that position, rather than being inherited unreviewed from unrelated prior UK engagements.
Step 6 - Document the resolution and rationale. Whatever combination of Steps 4's alternatives is ultimately agreed with the Control Group, the rationale, the authorisation boundary reasoning, and the confirmed legal position should be clearly documented in the engagement's scope and RoE documentation, both for internal audit trail purposes and to support any eventual C-RAF/HKMA-related review of the engagement's conduct.
Conclusion: The shared data centre's general building access controls cannot be validly authorised for testing by Silverpeak alone and should not be included without the data centre operator's own explicit, separately obtained consent, given both the authorisation-boundary principle and the added risk to unrelated co-tenants; and the team's informal, unverified assumption about Hong Kong's legal position must be properly and specifically confirmed (not carried over from UK experience) before any physical social engineering proceeds.
---
Background: Your firm delivers both an ongoing managed detection and response (MDR) service and, separately, red team engagements. Halcyon Wealth Management, an existing MDR client of your firm for the past two years, approaches your firm to also deliver an intelligence-led red team engagement, specifically because "you already know our environment so well, it'll be so much more efficient than starting with a new provider." Your firm's commercial team is enthusiastic, since this represents significant additional revenue from an existing relationship.
As the proposed Red Team Manager for this engagement, you are aware that the MDR team (a separate department within your firm) has deep, detailed knowledge of Halcyon's current detection rules, typical alert thresholds, and known historical gaps in their monitoring coverage - information that would be extremely valuable, arguably decisive, in planning a red team scenario intended to genuinely test detection and response capability. Halcyon's own internal Control Group has not raised any concern about the dual relationship; in fact, their CISO comments during scoping that "since your MDR team already sees everything, this should make the test even more realistic and thorough." Question: Identify the governance issue this scenario presents, and set out how you would address it before the engagement proceeds, including how you would respond to the CISO's comment.
See The answer in Explanation part below.
Explanation:
Step 1 - Identify the conflict of interest precisely. The core issue is a genuine, structural conflict of interest:
your firm is simultaneously the entity responsible for Halcyon's detection and response capability (via MDR) and the entity being asked to independently, objectively test that same capability (via the red team engagement). Using the MDR team's detailed internal knowledge of detection rules, thresholds, and known gaps to plan the red team scenario would not make the test "more realistic" in the way the CISO suggests - it would fundamentally compromise the test's independence and validity, because the Red Team would effectively already possess privileged insider knowledge of exactly how to evade detection, rather than the exercise genuinely, blindly testing whether Halcyon's actual detection and response capability holds up against a scenario designed independently of that inside knowledge.
Step 2 - Correct the CISO's misunderstanding directly and clearly. The CISO's comment reflects a genuine misunderstanding of what the exercise is meant to test, and this should be addressed directly, respectfully, but firmly: explain that the value of an intelligence-led red team exercise depends specifically on it being independent of and blind to the defensive capability being tested, and that incorporating detailed inside knowledge from the MDR relationship would not enhance realism - it would artificially inflate the Red Team's success in a way that tells Halcyon nothing genuine about how it would fare against an adversary who does not have that same privileged insight, thereby reducing, not increasing, the exercise's genuine value.
Step 3 - Assess whether the engagement can proceed at all, and under what conditions. Consistent with the governance domain's treatment of conflicts of interest, the correct approach is not necessarily to refuse the engagement outright, but to transparently identify and appropriately manage the conflict. Genuine management options include: structurally separating the red team delivery team from any access to or briefing from the MDR team's specific knowledge of Halcyon's environment (an "ethical wall" or information barrier, with the red team resourced and briefed as if approaching a genuinely new client, using only independently gathered threat intelligence and their own reconnaissance); ensuring the red team is staffed by consultants with no prior involvement in or exposure to Halcyon's MDR relationship; and being explicit and transparent with Halcyon's Control Group about exactly what separation measures are being put in place and why, so they understand and endorse the approach (rather than continuing to believe, per the CISO's comment, that MDR insight is a feature rather than a threat to validity).
Step 4 - Consider whether an independent second provider is the more defensible option. Depending on the severity of the conflict as assessed and Halcyon's own risk appetite once the issue is properly explained, it may be that the most defensible, credible option is to recommend Halcyon engage an entirely independent, unrelated provider for the red team engagement, preserving genuine independence, while your firm continues the separate MDR relationship - this should be presented as a genuine, professionally responsible option, not dismissed purely because it would forgo the additional revenue your firm's commercial team is keen to secure.
Step 5 - Do not let internal commercial enthusiasm override professional judgement. The scenario deliberately includes the detail that your firm's commercial team is enthusiastic about the revenue opportunity
- this is included to test whether the candidate will allow commercial pressure to override the more fundamental professional integrity issue. The correct answer explicitly resists this pressure, consistent with the syllabus principle that a Red Team Manager must actively and transparently manage tension between commercial interest and maintaining professional standards, escalating internally within your own firm if necessary to ensure the conflict is properly addressed rather than commercially waved through.
Step 6 - Document the decision and rationale either way. Whether the engagement proceeds (with robust, documented separation measures) or Halcyon is advised to seek an independent provider, the reasoning and any measures adopted should be clearly documented - both to protect your firm's professional credibility and to give Halcyon's own Control Group an accurate, honest basis for their own governance decision-making, consistent with the syllabus's broader emphasis on transparent, well-documented governance decisions.
Conclusion: This scenario presents a genuine structural conflict of interest between the MDR relationship and the red team engagement; the CISO's belief that MDR insight enhances realism should be corrected directly, since it would actually undermine the test's validity; and the engagement should only proceed, if at all, with robust, transparent, documented separation measures between the two service lines - with recommending an independent alternative provider being a legitimate and, depending on severity, potentially the more professionally defensible option, notwithstanding internal commercial pressure to proceed.
---
0 お客様のコメント