Home Quizzes Quiz Detail
Practice Quiz

CCRTS Practice Questions - CREST Certified Red Team Specialist (CCRTS) Exam

100 questions 5.0 rating Mobile friendly
$69.00

Unlock the full practice quiz

Get complete access to the questions, explanations and printable quiz resources.

Full access: unlock all quiz questions and explanations.
Printable review: access the full quiz PDF with correct answers after purchase.

About this Exam

Prepare with the CCRTS Practice Questions - CREST Certified Red Team Specialist (CCRTS) Exam practice quiz. This question bank includes 100 questions covering team, operator, technique, engagement, and windows. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

Sample Questions

Question 1
During a red team engagement, which MITRE ATT&CK tactic describes the adversary's goal of maintaining a foothold after initial compromise?
Initial Access
Persistence
Defense Evasion
Collection
Question 2
A red team operator needs to enumerate Active Directory users without triggering LDAP query anomaly alerts. Which approach is most operationally secure?
Run ldapsearch with anonymous bind from an external IP
Use BloodHound's SharpHound collector with stealth options and randomised delay intervals
Execute net user /domain from a newly compromised workstation without delay
Perform a zone transfer against the domain's DNS server
Question 3
Which Kerberos attack abuses accounts that have 'Do not require Kerberos preauthentication' set and does NOT require any domain credentials to execute?
Kerberoasting
AS-REP Roasting
Pass-the-Ticket
Silver Ticket
Question 4
An operator wants to bypass Windows Defender AMSI (Antimalware Scan Interface) before loading a PowerShell-based implant. Which technique directly patches the AmsiScanBuffer function in memory?
Encoding the payload with base64 and piping it through iex
Disabling PowerShell Constrained Language Mode via registry
Patching the AmsiScanBuffer return value to AMSI_RESULT_CLEAN in the process memory
Setting the AMSI_DISABLE environment variable before launching PowerShell
Question 5
During initial access via phishing, a red team operator uses a lure that routes the target through an Adversary-in-the-Middle (AiTM) proxy. What primary capability does this technique provide that standard phishing does not?
Delivery of macro-enabled Office documents
Capture of session cookies to bypass MFA
Automated credential spraying against the target's email gateway
Exfiltration of files from the victim's mailbox

Ready to test your knowledge?

Buy Now to Access

Additional Information

CCRTS Practice Questions - CREST Certified Red Team Specialist (CCRTS) Exam

This practice set contains 100 questions from the matching question bank and focuses on team, operator, technique, engagement, and windows. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Frequently Asked Questions

This quiz contains a total of 100 practice questions carefully selected to test your knowledge on this subject.
Yes, you will have exactly 0 minutes to complete the exam. A countdown timer will be visible once you start.
Yes, you can retake this practice test as many times as you need. The questions and options may be randomized on subsequent attempts to ensure comprehensive learning.

Reviews

5.0

Based on 0 reviews

Leave a Review

No reviews yet. Be the first to review!