CREST Red Team Specialist (CCRTS) Certification Sample Questions

Red Team Specialist Dumps, CCRTS Dumps, CCRTS PDF, Red Team Specialist VCE, CREST CCRTS VCE, CREST Red Team Specialist PDFThe purpose of this Sample Question Set is to provide you with information about the CREST Red Team Specialist exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CCRTS certification test. To get familiar with real exam environment, we suggest you try our Sample CREST Red Team Specialist Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual CREST Certified Red Team Specialist (CCRTS) certification exam.

These sample questions are simple and basic questions that represent likeness to the real CREST CCRTS exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium CREST Red Team Specialist Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

CREST CCRTS Sample Questions:

01. You need to build a picture of a target's external footprint by collecting registration records, DNS data and public code repositories without touching its systems. This activity belongs to which phase of the engagement?
a) Reporting
b) Exploitation
c) Cleanup
d) Reconnaissance
 
02. What is a common reason red teams execute through living-off-the-land binaries (LOLBins)?
a) They are signed, trusted system binaries that can be abused to execute code
b) They consume fewer system resources than custom tools
c) They are always compiled in the Go programming language and so cannot be signatured
d) They are widely believed to be exempt from all inbound and outbound network filtering
 
03. A red teamer finds artefacts under C:\Windows\System32\Tasks\ on a compromised host. Which persistence mechanism does that location indicate?
a) Registry run-key hijack
b) WMI event subscription
c) Scheduled tasks
d) Service binary hijack
 
04. Your C2 traffic is detected because its requests carry repetitive, non-browser-like headers.
What should you modify to reduce that detection?
a) Base64-encode the payload body of each request
b) Set realistic browser User-Agent and Accept headers on requests
c) Switch the entire channel over to DNS-only tunnelling for every request
d) Place the raw binary command data directly into each request's URL path
 
05. Which of the following best reflects operational security (OPSEC) in a red team engagement?
a) Encrypting client credentials once the engagement has finished
b) Routing every outbound connection through a commercial VPN service
c) Restricting all attack activity to the client's normal working hours
d) Avoiding attribution of the team so the simulation stays realistic
 
06. An externally reachable login portal allows unlimited password attempts with no lockout.
Which attack vector does this weakness most directly support?
a) Cross-site request forgery
b) DNS rebinding
c) Credential stuffing
d) SQL injection through the login form
 
07. Credential stuffing succeeds because which kind of passwords are reused across multiple sites?
a) randomly generated
b) breached
c) regularly rotated
d) sufficiently long
 
08. Which technique is used to reach a concealed service through a perimeter firewall without exposing an open port to routine scanning?
a) Binding to the loopback interface
b) Encrypting the payload with AES
c) Log wiping
d) Port knocking
 
09. During an engagement your HTTP beacon implant is blocked by a newly added proxy rule mid-operation.
What should the implant ideally do next?
a) Fall back to a secondary command-and-control channel over DNS so tasking can resume through a different egress path
b) Fail silently and cease all communication
c) Alert the target's SOC to the connectivity issue
d) Uninstall itself from the host
 
10. Which stealth strategy helps evade heuristic detection when performing lateral movement over SMB?
a) Tunnelling SMB over ICMP
b) Using multi-threaded bruteforce (credential spraying)
c) Using named pipes and the service control manager (SCM)
d) Running commands in cleartext

Answers:

Question: 01
Answer: d
Question: 02
Answer: a
Question: 03
Answer: c
Question: 04
Answer: b
Question: 05
Answer: d
Question: 06
Answer: c
Question: 07
Answer: b
Question: 08
Answer: d
Question: 09
Answer: a
Question: 10
Answer: c

Note: For any error in CREST Certified Red Team Specialist (CCRTS) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (113 votes)