⚡ CREST Registered Tester (CRT)
The CRT is an internationally recognized certification issued by CREST (primarily recognized in the UK, Europe, and Commonwealth countries). It is designed to validate a candidate’s technical skills in both infrastructure and web application penetration testing, confirming they can execute core auditing operations professionally.
📋 Exam Specifications
- Format: Hands-on practical examination.
- Passing Criteria: Achieved by obtaining a passing grade on the practical assessment.
- Exam Targets: Covers multiple infrastructure hosts (enumerating OS platforms, port configurations, and exploiting services) and web targets (mapping OWASP Top 10 vulnerabilities).
🛠️ Core Skills Validated
- Infrastructure Network Auditing: Mapping network systems, identifying outdated systems software, and verifying patch controls.
- Windows & Linux Service Exploitation: Compromising network protocols (FTP, SSH, SMB, SNMP, SMTP) and identifying password reuse flaws.
- Core Web Security Audits: Detecting SQL injections, Cross-Site Scripting (XSS), insecure configuration files, and authentication weaknesses.
- Database Auditing: Mapping database listeners and executing queries on compromised SQL database endpoints.
- Information Gathering: Passive DNS mapping and active host sweeps.