최신CREST Certified Red Team Manager - Multiple Choice Long Form - CCRTM-MCLF무료샘플문제
문제1
Which of the following best describes the value of the "Diamond Model" of intrusion analysis in threat intelligence work?
Which of the following best describes the value of the "Diamond Model" of intrusion analysis in threat intelligence work?
정답: A
설명: (KoreaDumps 회원만 볼 수 있음)
문제2
Why is it important for a Red Team Manager to understand multiple regional frameworks even if their firm primarily delivers CBEST engagements?
Why is it important for a Red Team Manager to understand multiple regional frameworks even if their firm primarily delivers CBEST engagements?
정답: B
설명: (KoreaDumps 회원만 볼 수 있음)
문제3
Which of the following is the most appropriate consideration when negotiating engagement scope against a client's fixed budget, from a professional management perspective?
Which of the following is the most appropriate consideration when negotiating engagement scope against a client's fixed budget, from a professional management perspective?
정답: B
설명: (KoreaDumps 회원만 볼 수 있음)
문제4
Which of the following should the Rules of Engagement explicitly define regarding communication during the engagement?
Which of the following should the Rules of Engagement explicitly define regarding communication during the engagement?
정답: C
설명: (KoreaDumps 회원만 볼 수 있음)
문제5
Which of the following best describes the appropriate governance relationship between a firm's internal audit function and an intelligence-led testing programme?
Which of the following best describes the appropriate governance relationship between a firm's internal audit function and an intelligence-led testing programme?
정답: A
설명: (KoreaDumps 회원만 볼 수 있음)
문제6
Which of the following best describes appropriate management practice regarding a red team provider's own internal incident response plan, in the event the provider's own infrastructure or systems were compromised?
Which of the following best describes appropriate management practice regarding a red team provider's own internal incident response plan, in the event the provider's own infrastructure or systems were compromised?
정답: B
설명: (KoreaDumps 회원만 볼 수 있음)
문제7
Why is early identification of stakeholders (e.g., business owners of in-scope systems, legal, data protection officer, IT operations leadership) considered essential during scoping?
Why is early identification of stakeholders (e.g., business owners of in-scope systems, legal, data protection officer, IT operations leadership) considered essential during scoping?
정답: C
설명: (KoreaDumps 회원만 볼 수 있음)
문제8
A client's General Counsel asks whether engaging a red team provider removes the client's own regulatory reporting obligations if the test uncovers evidence of an actual, pre-existing compromise (unrelated to the test itself). What is the most accurate answer?
A client's General Counsel asks whether engaging a red team provider removes the client's own regulatory reporting obligations if the test uncovers evidence of an actual, pre-existing compromise (unrelated to the test itself). What is the most accurate answer?
정답: A
설명: (KoreaDumps 회원만 볼 수 있음)
문제9
Which best describes the relevance of export control regulations (such as those under the Wassenaar Arrangement framework, as implemented in relevant national law) to red team tooling?
Which best describes the relevance of export control regulations (such as those under the Wassenaar Arrangement framework, as implemented in relevant national law) to red team tooling?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)
문제10
Which of the following best describes the governance rationale for the internal Red Team provider organisation applying rigorous internal quality assurance review to a report before it is delivered to the client?
Which of the following best describes the governance rationale for the internal Red Team provider organisation applying rigorous internal quality assurance review to a report before it is delivered to the client?
정답: A
설명: (KoreaDumps 회원만 볼 수 있음)
문제11
Which EU regulation formally mandates Threat-Led Penetration Testing (TLPT) for certain significant financial entities, using TIBER-EU as its operational basis?
Which EU regulation formally mandates Threat-Led Penetration Testing (TLPT) for certain significant financial entities, using TIBER-EU as its operational basis?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)
문제12
A firm undergoing CBEST discovers during the Threat Intelligence phase that a plausible, highly relevant threat actor primarily targets a third-party payment processor integrated with the firm's core banking platform.
What is the most appropriate governance action?
A firm undergoing CBEST discovers during the Threat Intelligence phase that a plausible, highly relevant threat actor primarily targets a third-party payment processor integrated with the firm's core banking platform.
What is the most appropriate governance action?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)
문제13
Which of the following statements about scope creep during an engagement is most accurate?
Which of the following statements about scope creep during an engagement is most accurate?
정답: B
설명: (KoreaDumps 회원만 볼 수 있음)
문제14
Which of the following best describes a key legal reason for defining explicit "prohibited actions" (e.g., no destructive denial-of-service, no exfiltration of real customer data) within engagement documentation?
Which of the following best describes a key legal reason for defining explicit "prohibited actions" (e.g., no destructive denial-of-service, no exfiltration of real customer data) within engagement documentation?
정답: A
설명: (KoreaDumps 회원만 볼 수 있음)
문제15
Which of the following best describes the purpose of correlating the Red Team's detailed activity logs with the Blue Team's own monitoring/detection logs during closure?
Which of the following best describes the purpose of correlating the Red Team's detailed activity logs with the Blue Team's own monitoring/detection logs during closure?
정답: A
설명: (KoreaDumps 회원만 볼 수 있음)