CREST Certified Red Team Manager - Multiple Choice Long Form (CCRTM-MCLF) Free Practice Test
Question 1
Why might a smaller, lower-risk Authorized Institution not be required to complete a full iCAST engagement under C-RAF?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 2
Which of the following would be the LEAST appropriate basis for determining the final scope of an engagement?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 3
During a CBEST Red Team phase, testers identify an opportunity to pivot into a system that appears to be out of the agreed scope but is trivially reachable from an in-scope host. What is the correct action?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 4
Which of the following best describes the purpose of maintaining and periodically updating internal methodology and knowledge management resources within a red team practice?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 5
Which of the following best describes the concept of "Priority Intelligence Requirements" (PIRs) in the context of scoping a threat intelligence workstream for a red team engagement?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 6
In the TIBER-EU model, what happens to the results and lessons learned at the aggregate, cross-entity level, while individual entity results remain confidential?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 7
Which of the following best reflects how the RoE should treat the use of testers' personal (non-client-issued, non-provider-issued) devices or accounts during an engagement?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 8
A subcontractor is engaged by the primary Red Team provider to deliver part of a client engagement. What is the most important legal consideration regarding the subcontractor's authorisation to test the client's systems?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 9
Which of the following best describes the appropriate treatment of legacy or end-of-life systems discovered to be in scope, where compromise could cause disproportionate, hard-to-remediate disruption?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 10
Which of the following best describes the ultimate management objective that resourcing, risk management, governance discipline, and quality assurance practices in this domain are all working towards?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 11
Which role in iCAST is most directly comparable to the "Threat Intelligence Provider" role in CBEST and TIBER-EU?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).