Search for this credential and you will be told, repeatedly, that it is a sixty minute exam with sixty questions and a two thirds pass mark. Those numbers are real. They describe one of four marked sections.
The CREST Certified Red Team Specialist exam is two separate sittings of three hours each. A written exam splits into a one hour multiple-choice test and a two hour written scenario. A practical exam splits into a red team assault course and a section on operational security and tradecraft, the second of which is scored automatically from whether the defenders caught you. Four sections, 480 marks in total, four separate pass marks, and failing one fails the part it sits in. This walkthrough sets out the real structure, the marking, the eight syllabus areas, and what the exam environment actually gives you to work with.
What Does the CREST Certified Red Team Specialist Exam Involve?
The CREST Certified Red Team Specialist exam has two distinct parts. A written exam of three hours, containing a one hour multiple-choice test and a two hour written scenario, and a practical exam of three hours, containing a red team assault course and an operational security and tradecraft section. Candidates may sit them in either order, though CREST suggests starting with the written.

Before either sitting, candidates are given a threat intelligence pack. It carries the background of the target, the scenario context, the threat actor being emulated, the goals of the engagement, and usable data such as tactics, techniques and procedures, domains and user names. That pack is not scene setting. It is the brief you are assessed against, because the whole assessment is built on simulating a specific adversary rather than demonstrating generic attack skill.
The practical labs are built per candidate. Each is a unique instance, constructed and verified before it is presented, and every answer is marked automatically. There is no examiner watching you work and no partial credit for an approach that did not land.
What Are the Real CCRTS Exam Details?
CCRTS runs to six hours of assessment across two sittings, with an additional 15 minutes of reading time before the written scenario and another 15 before the practical exam. There are no prerequisites. The exam is listed at 400 US dollars and results are delivered through Pearson VUE, and the syllabus is published as eight areas with no weightings attached to any of them.
| Field | Value |
|---|---|
| Exam name | CREST Certified Red Team Specialist |
| Exam code | CCRTS |
| Written exam | 3 hours: multiple-choice test 1 hour, written scenario 2 hours |
| Practical exam | 3 hours: assault course and tradecraft sections |
| Reading time | 15 minutes before the written scenario, 15 before the practical |
| Total marks | 480 across four sections |
| Prerequisites | None |
| Listed price | $400 |
| Results platform | Pearson VUE |
The written exam is closed book, and that applies to both of its components. No books, no notes, no internet access, no electronic devices. Someone used to writing engagement reports with documentation open in a second window should treat the two hour scenario as the harder half of that sitting for exactly this reason.
The practical exam works differently. Files can be pre-uploaded through CRESTDrive ahead of the day and are available inside the environment, so tooling you rely on does not have to be rebuilt under time pressure. Two virtual machines are provided for familiarisation beforehand, one running Kali Linux and one running Windows, and a licensed copy of Proxifier is available in the exam environment. CREST publishes all of this on its own CCRTS certification page, and it is worth reading the notes for candidates in full before booking.
If you want to calibrate against the multiple-choice component specifically, working CCRTS sample questions is the cheapest way to find the gaps in the breadth the syllabus expects.
How Is the Written Exam Marked?
The written exam carries 180 marks. The multiple-choice test is worth 60 and requires at least two thirds, meaning 40 marks. The written scenario is worth 120 and also requires at least two thirds, meaning 80 marks. Passing one component while failing the other results in failure of the written exam overall.
| Section | Part | Marks | Pass mark |
|---|---|---|---|
| Multiple-choice test | Written | 60 | 40 (two thirds) |
| Written scenario | Written | 120 | 80 (two thirds) |
| Red team assault course | Practical | 180 | 120 (two thirds) |
| Tactics, tradecraft and operational security | Practical | 120 | 60 (one half) |
The ordering inside the written exam is fixed even though the ordering between the two exams is not. Candidates must start with the multiple-choice test and then move to the written scenario, though questions can be answered in any order within each component.
What the scenario component is really testing
Two hours and 120 marks is a lot of weight for a written piece, and it sits at twice the value of the multiple-choice test. The syllabus areas that feed it are the ones that have nothing to do with running a tool: scoping, risk, record keeping and reporting, threat intelligence interpretation, and client communications. This is the section that separates a red teamer from an operator.
When you find out
Multiple-choice results appear at the end of the sitting in your Pearson VUE account, with a breakdown by area showing how you performed in each. The written scenario is marked by hand, so that result and the overall written outcome arrive within 20 days. Practical results are usually available within 24 hours and occasionally up to 48 where additional verification is needed.
What Happens in the Practical Exam?
The practical exam runs three hours and carries 300 marks across two sections. The red team assault course is worth 180 and asks the candidate to compromise an enterprise environment along an attack path informed by the threat intelligence pack. The tactics, tradecraft and operational security section is worth 120 and is scored on detection results rather than on completed objectives.

That second sentence is the important one, because it means the two sections can pull against each other. The assault course rewards progress. The tradecraft section rewards not being seen making it. A candidate who kicks doors down efficiently can pass the first and fail the second, and failing one section fails the practical exam overall.
The environment supports a realistic approach rather than a lab one. Each instance is unique and built for that candidate, files can be pre-uploaded, and the familiarisation machines let you confirm your tooling works with the versions available before the clock starts. All marking is automatic, so an approach that was conceptually right but did not produce the artefact scores nothing.
In practice, this means preparation has to include operating quietly under time pressure, not just operating. Rehearsing a full engagement end to end, with throttled traffic and deliberate choices about which detections to trigger, matters more than rehearsing individual techniques.
Why Does the Tradecraft Section Use a Lower Pass Mark?
The tactics, tradecraft and operational security section requires only half its 120 marks to pass, against two thirds on the other three sections. The marks are auto calculated from detection results, so the threshold reflects a reality of adversary simulation: a competent red team is detected sometimes, and the exam is measuring restraint rather than invisibility.
Reading it as a soft option would be a mistake. Half of 120 is still 60 marks earned by not being caught, in an environment instrumented to catch you, while simultaneously making enough progress to clear 120 of 180 on the assault course. The lower threshold acknowledges that the two objectives conflict.
The syllabus is candid about what is being assessed here. It talks about limiting opportunities for detection while also providing detection opportunities in line with the simulation’s threat intelligence, which is a more sophisticated goal than pure stealth. A red team emulating a noisy actor should be noisy in that actor’s way. This is where the syllabus expects fluency in adversary tactics and techniques as a map of behaviour rather than as a checklist of tools, alongside the cyber kill chain phases that structure an engagement.
What Do the Eight Syllabus Areas Cover?
CREST publishes the CCRTS syllabus as eight areas with no weightings: Soft Skills and Assessment Management, Core Technical Skills, Reconnaissance, Implants, Initial Access, Lateral Movement and Privilege Escalation, Evasion, and Egress and Command and Control. The absence of weightings means no area can be treated as optional, and the areas map onto the phases of an engagement rather than onto categories of knowledge.
| Syllabus area | What it covers |
|---|---|
| Soft Skills and Assessment Management | Law and compliance, scoping, risk, record keeping and reporting, threat intelligence, client communications, operational security, social engineering, physical security, threat modelling |
| Core Technical Skills | Networking, discovery and mapping, cryptography, file system permissions, audit techniques, automation and scripting |
| Reconnaissance | Registration records, DNS, internet reconnaissance, and third party or cloud provider discovery |
| Implants | Implant design and assessment, trojanised file formats, persistence, and physical implants |
| Initial Access | Email and application delivery, supply chain attacks, perimeter attacks, insider threat simulation, remote credential theft |
| Lateral Movement and Privilege Escalation | Active Directory and cloud directory abuse, host and user enumeration, operating system vulnerabilities, software and file enumeration, browser and application exploitation, user interaction |
| Evasion | Host antivirus and endpoint detection evasion, network intrusion detection, perimeter controls, stealth |
| Egress and Command and Control | Reverse communications, tunnelling, attack source obfuscation, secure egress |
The first area is the one candidates from a pure testing background tend to underestimate. It is by some distance the largest by sub-topic count, and it is almost entirely non-technical: scoping an engagement properly, measuring the risk of an attack path before taking it, keeping an audit log detailed enough to assist a customer afterwards, and running a communication strategy with defined escalation paths. Those are the skills the two hour written scenario draws on.
The technical areas read as a single engagement in sequence. Reconnaissance produces the target picture, implants and initial access get you in, lateral movement and privilege escalation get you where you need to be, and evasion and egress determine whether any of it survives contact with the defenders.
Which Legal Knowledge Does CCRTS Expect?
The syllabus opens with law and compliance and treats it as examinable content rather than as a disclaimer. Candidates need awareness of legislation covering computer misuse and personal data in the regions they work, knowledge of the written authority required to operate legally, understanding of client confidentiality and non-disclosure obligations, and awareness of when law enforcement must be notified.
CREST gives worked examples rather than leaving it abstract. For the United Kingdom it names the Computer Misuse Act 1990 and its amendments for computer misuse, the Data Protection Act 2018 for personal data, and CBEST as the sector framework for financial services. The prosecution service publishes guidance on those offences, which is more use to a tester than the statute text. The syllabus expects a candidate to be able to give examples of both compliance and non-compliance.
Two points make this harder than it looks. The first is multinational engagements, where several legal regimes apply at once and the syllabus explicitly asks for awareness of that complexity. The second is out of hours physical work and reconnaissance, where notifying law enforcement in advance can be the difference between an authorised simulation and an incident.
The practical consequence is a document. The letter of authority is named in the syllabus, and knowing what it must contain and who has to sign it is a fair exam question in a way that reciting statute section numbers is not.
How Should You Prepare for the CCRTS Exam?
Preparation splits along the same line the exam does. The written exam rewards breadth and the ability to explain a decision in prose without documentation to hand; the practical rewards operating quietly under time pressure in an unfamiliar environment. Preparing for one does very little for the other, so plan two tracks.
- Read the eight syllabus areas end to end and mark every sub-topic you have never actually done, because the absence of weightings means no area can be written off as minor.
- Start with Soft Skills and Assessment Management, the largest area by sub-topic count and the one that feeds the two hour written scenario, working scoping, risk, reporting and client communications rather than tooling.
- Cover the law and compliance material for the regions you work in, including what a letter of authority must contain and when law enforcement notification applies.
- Rehearse the technical areas as a single engagement in sequence, from reconnaissance through implants and initial access to lateral movement, rather than as separate techniques.
- Practise evasion and egress deliberately against instrumented defences, since the tradecraft section is scored on detection results rather than on objectives completed.
- Sit timed written practice closed book, with no notes and no internet, because that is the condition both written components are taken under.
- Use the familiarisation virtual machines before exam day to confirm your tooling works with the versions provided, and prepare the files you intend to pre-upload through CRESTDrive.
The iSecPrep CCRTS exam resources page collects the study material for the written half in one place.
Who the Credential Is Aimed At
CCRTS has no prerequisites, which is unusual for an assessment of this shape and does not mean it is an entry point. The exam assumes a candidate who has already compromised enterprise environments professionally, because three hours is not long enough to learn the assault course while sitting it.
The credential fits a specific transition: a penetration tester moving into adversary simulation. Those are different jobs. Testing finds and proves vulnerabilities against a scoped target list. Red teaming emulates a named threat actor to measure whether an organisation’s protective and detective controls actually work, which is why the marking scheme cares as much about whether you were seen as about what you reached.
That difference also explains the weight given to the non-technical area. A red team engagement produces a judgement about an organisation’s defensive posture, and that judgement has to be communicated to people who were not in the room.
Frequently Asked Questions
How long is the CCRTS exam?
Six hours of assessment across two sittings: a three hour written exam and a three hour practical exam, plus 15 minutes of reading time before the written scenario and another 15 before the practical.
Is the CCRTS exam really 60 questions in 60 minutes?
No. That describes the multiple-choice test, which is one of four marked sections and worth 60 of the 480 marks available. The written scenario, assault course and tradecraft sections carry the rest.
What is the pass mark for CCRTS?
Two thirds on the multiple-choice test, the written scenario and the assault course, and one half on the tactics, tradecraft and operational security section. Failing one section fails the part it sits in.
Can I take the practical exam before the written one?
Yes. CREST allows either order and suggests starting with the written exam. Within the written exam the order is fixed: multiple choice first, then the scenario.
Are there prerequisites for CCRTS?
None. CREST states plainly that there are no prerequisites, though the practical exam assumes professional experience compromising enterprise environments rather than lab familiarity.
Is the CCRTS written exam open book?
No. Both written components are closed book, with no books, written notes, internet access or other electronic devices permitted.
How is the tradecraft section scored?
Automatically, from detection results. The marks reflect how visible your activity was to the instrumented defences rather than how many objectives you completed.
How quickly do CCRTS results arrive?
Multiple-choice results appear at the end of that sitting with an area breakdown. The written scenario and overall written result take up to 20 days. Practical results usually arrive within 24 hours and occasionally take 48.
What tooling is available in the practical exam?
Familiarisation machines running Kali Linux and Windows, a licensed copy of Proxifier in the exam environment, and any files you pre-upload through CRESTDrive before the day.
Does CREST publish weightings for the CCRTS syllabus?
No. Eight areas are published with no percentages attached, which means preparation has to cover all of them rather than being ranked by importance.
Conclusion
The most useful thing to know about CCRTS is the thing most summaries leave out: it is six hours across four separately marked sections, and clearing three of them is a fail. The multiple-choice test that dominates search results is the smallest of the four.
That shape should drive preparation. The written scenario carries twice the marks of the multiple-choice test and draws almost entirely on scoping, risk, reporting and communication rather than tooling. The practical exam asks you to make real progress while staying quiet enough to earn 60 marks from detection results. Read the eight syllabus areas honestly, work the non-technical area first because it is the largest, and rehearse full engagements rather than individual techniques. Sample questions in the multiple-choice format are the fastest way to find where the breadth is thin. If you are still deciding where CCRTS sits against the testing and threat intelligence tracks, the CREST certification hub is the place to start.
