100+ Free CCRTS Practice Questions
Prepare for the CREST Certified Red Team Specialist (CCRTS) exam with instant access — no signup required.
Loading practice questions...
Explore More CREST Penetration Testing Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CCRTS Exam
120/180
Assault Course Pass Mark
CREST CCRTS Syllabus v2.1
60/120
Tradecraft Section Pass Mark
CREST CCRTS Syllabus v2.1
3 hours
Practical Exam Duration
CREST
8 domains
Syllabus Knowledge Areas
CREST CCRTS Syllabus v2.1
Auto-scored
Tradecraft Scoring Method
CREST CCRTS Syllabus v2.1
Expert
Certification Level
CREST
The CREST CCRTS is an expert-level hands-on red team certification delivered via Pearson VUE. The practical exam includes a Red Team Assault Course (minimum 120/180 marks) and an auto-scored Tradecraft & Operational Security component (minimum 60/120 marks based on detection results). The syllabus spans eight domains: soft skills, core technical skills, reconnaissance, implants, initial access, lateral movement and privilege escalation, evasion, and egress/C2. This practice exam tests theoretical knowledge; passing the real exam requires hands-on red team expertise in enterprise exploitation and OPSEC tradecraft.
Sample CCRTS Practice Questions
Try these sample questions to test your CCRTS exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1During a red team engagement, which MITRE ATT&CK tactic describes the adversary's goal of maintaining a foothold after initial compromise?
2A red team operator needs to enumerate Active Directory users without triggering LDAP query anomaly alerts. Which approach is most operationally secure?
3Which Kerberos attack abuses accounts that have 'Do not require Kerberos preauthentication' set and does NOT require any domain credentials to execute?
4An operator wants to bypass Windows Defender AMSI (Antimalware Scan Interface) before loading a PowerShell-based implant. Which technique directly patches the AmsiScanBuffer function in memory?
5During initial access via phishing, a red team operator uses a lure that routes the target through an Adversary-in-the-Middle (AiTM) proxy. What primary capability does this technique provide that standard phishing does not?
6Which MITRE ATT&CK technique does 'Pass-the-Hash' fall under?
7A red team uses DNS over HTTPS (DoH) as its C2 channel. What is the primary operational security benefit of this approach?
8Which of the following best describes the purpose of a 'redirector' in red team C2 infrastructure?
9During a CREST red team engagement, a candidate is required to demonstrate operational security (OPSEC). Which action would MOST undermine OPSEC during an engagement?
10Kerberoasting (T1558.003) is effective because of which fundamental design decision in Kerberos?
About the CCRTS Exam
The CREST Certified Red Team Specialist (CCRTS) is an expert-level practical certification assessing the ability to conduct threat intelligence-led adversary simulation engagements. Candidates demonstrate red team tradecraft, OPSEC discipline, and advanced enterprise exploitation in a 3-hour assault course. This practice bank covers the full CCRTS body of knowledge: MITRE ATT&CK TTPs, Kerberos attacks, Active Directory exploitation, C2 infrastructure, evasion, and CBEST/TIBER-EU framework knowledge.
Assessment
Performance-based assessment
Time Limit
3 hours (practical) + 3 hours (written, if taken)
Passing Score
120/180 Assault Course + 60/120 Tradecraft
Exam Fee
Contact Pearson VUE or CREST for pricing (CREST (Pearson VUE delivery))
CCRTS Exam Content Outline
Lateral Movement & Privilege Escalation
Kerberoasting, AS-REP Roasting, Pass-the-Hash, Golden/Silver Ticket, DCSync, ADCS ESC1, Unconstrained/Constrained Delegation, BloodHound, NTLM relay, PrintNightmare, ZeroLogon
Evasion
AMSI bypass, ETW patching, EDR evasion, BYOVD, reflective DLL injection, BOFs, LOLBins, application control bypass, sandbox evasion, DLL hijacking
Egress & Command and Control
Redirectors, malleable C2 profiles, sleep jitter, DNS/HTTPS/SMB C2, domain fronting, Microsoft Graph API C2, Cobalt Strike Beacon, Sliver, traffic obfuscation, data exfiltration
Adversary TTPs & MITRE ATT&CK
ATT&CK tactic and technique mapping, Cyber Kill Chain, adversary simulation, ATT&CK Navigator, threat intelligence-led engagement planning, supply chain attacks
Initial Access & Reconnaissance
Passive recon (CT logs, theHarvester, OSINT), phishing, AiTM attacks, LLMNR/NBT-NS poisoning, Responder, social engineering, cloud recon (AzureHound, ROADtools)
Implants & Persistence
Process injection (VirtualAllocEx, section mapping, reflective loading), Windows and Linux persistence, token impersonation, Potato attacks, COM hijacking, registry run keys
Soft Skills & Assessment Management
Computer Misuse Act 1990, CBEST/TIBER-EU/STAR-FS frameworks, rules of engagement, deconfliction procedures, crown jewel identification, purple teaming, red team reporting (MTTD/MTTR)
How to Pass the CCRTS Exam
What You Need to Know
- Passing score: 120/180 Assault Course + 60/120 Tradecraft
- Assessment: Performance-based assessment
- Time limit: 3 hours (practical) + 3 hours (written, if taken)
- Exam fee: Contact Pearson VUE or CREST for pricing
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CCRTS Study Tips from Top Performers
Frequently Asked Questions
What is the CREST CCRTS exam format?
The CCRTS practical exam comprises two components: the Red Team Assault Course (maximum 180 marks, pass mark 120) and the Tactics, Tradecraft & Operational Security section (maximum 120 marks, pass mark 60), which is auto-scored based on what defenders detect during the assault course. There is also an optional written exam (3 hours: 60-mark MCQ + 120-mark written scenario) with separate pass marks. Both practical sections must be passed. The exam is delivered via Pearson VUE.
What technical areas does the CCRTS syllabus cover?
The CCRTS syllabus v2.1 covers eight domains: Soft Skills & Assessment Management; Core Technical Skills (networking, cryptography, scripting); Reconnaissance (OSINT, DNS, cloud); Implants (evasion, persistence, physical implants); Initial Access (phishing, AiTM, supply chain); Lateral Movement & Privilege Escalation (AD attacks, Kerberos, credential dumping); Evasion (AV/EDR bypass, AMSI, ETW, LOLBins); and Egress/C2 (redirectors, tunnelling, traffic obfuscation).
What is the relationship between CCRTS and CBEST/TIBER-EU?
The CCRTS is designed to certify specialists capable of conducting threat intelligence-led simulated attack engagements such as CBEST (UK financial sector), TIBER-EU (European financial sector), and STAR-FS (SWIFT member testing). These frameworks require separate, independent Threat Intelligence Providers and use a targeted attack lifecycle model (Cyber Kill Chain + MITRE ATT&CK). CCRTS-certified individuals demonstrate the technical capability to lead the red team component of such engagements.
How does the tradecraft scoring work in the CCRTS?
The Tactics, Tradecraft & Operational Security component of the CCRTS practical is auto-scored based on detection results — specifically what defensive tools and monitoring systems detect during the candidate's assault course attempt. A candidate who achieves objectives with a minimal detectable footprint scores higher on tradecraft. This is distinct from the assault course score, which measures whether objectives were completed.
What prerequisites are needed for the CCRTS?
CREST does not mandate formal prerequisites for CCRTS, but the certification is positioned as expert-level. Candidates are expected to have strong practical experience in advanced penetration testing or red teaming, be comfortable with Active Directory attacks, C2 operations, evasion techniques, and OPSEC discipline. Passing the CPSA and potentially CCT Infrastructure are recommended stepping stones.
Is this practice test like the real CCRTS exam?
No — the real CCRTS practical exam requires you to actually compromise live enterprise environments under time pressure while demonstrating OPSEC discipline, with your tradecraft auto-scored by detection results. This practice bank is a theoretical multiple-choice resource testing your knowledge of the techniques, tools, frameworks, and concepts in the CCRTS syllabus. Use it to solidify knowledge, then build hands-on skills in lab environments before attempting the real exam.