Passing the CRTO means proving you can run a full Cobalt Strike–driven red team operation against Active Directory while staying quiet enough to satisfy an OPSEC-weighted scoring model. For a working professional, that outcome is realistic in about 4–8 weeks of focused practice, roughly 60–120 hours of study, on a budget of about £399 for the official Red Team Ops course bundled with the exam. This guide breaks down how to prepare for CRTO efficiently: what the exam actually tests, the prerequisites worth verifying first, an ordered study sequence, the mistakes that sink otherwise capable candidates, and the point where mentor-supported materials from us at Cyber Services shorten the trial-and-error curve.
Table of contents
What the CRTO exam actually tests
CRTO is Zero-Point Security’s practical red team certification, built around the Red Team Ops (RTO) course and a hands-on adversary-simulation exam. The course covers the full attack lifecycle against Windows and Active Directory environments, with Cobalt Strike as the primary command-and-control framework: initial access, lateral movement, privilege escalation, and long-term persistence, all with a stealth and OPSEC emphasis.
The exam is a practical, objective-based lab challenge with no written report. You get 48 hours of lab time, typically spread across four calendar days, inside a browser-accessible environment. It runs like a capture-the-flag exercise; candidate write-ups describe eight available flags with six required to pass. Community analyses point to a 100-point model where roughly 85 points is the pass mark, with points split between achieving the technical objective and demonstrating operational security.
That scoring split is the single most important thing to internalize. Half your grade rewards compromise; the other half rewards how quietly you did it. A candidate who reaches domain admin with loud, alert-triggering tradecraft can still fall short. Understanding this structure is the foundation of any credible plan for how to prepare for CRTO.
On logistics: the RTO course plus CRTO exam typically bundles at about £399, including course content, lab access, and at least one exam attempt. Recent analyses report that exam attempts are effectively unlimited at no extra cost and that the certification does not expire once earned. If you want a broader map of how this credential sits alongside offensive certifications you may already hold, our CRTO exam writeup collects the domain-level detail in one place.

Prerequisites checklist before you book
Before you lock in an exam window, confirm you actually meet the ground-level requirements. Booking too early wastes lab time you paid for and forces you to relearn fundamentals under a running clock.
- Solid Windows fundamentals: services, processes, PowerShell, and the registry.
- Working knowledge of Active Directory: domains, trusts, GPOs, OU structure, and Kerberos.
- Prior offensive experience at roughly OSCP, CPTS, or PNPT level so core attack primitives are already familiar.
- Comfort with at least one scripting language (PowerShell, Python, or C#) for automation and tooling.
- Familiarity with red team tooling: Cobalt Strike, C2 infrastructure tradecraft, beacons, and stagers.
- A practical grasp of OPSEC for offensive work: log awareness, EDR basics, and avoiding noisy activity.
- The ability to dedicate 8–12 hours per week for at least a month to structured labs and reading.
- A stable internet connection and a quiet environment for the 48 hours of exam lab time.
If you cannot confidently check most of these, add ramp-up time before booking rather than compressing it inside the exam. If your gap is offensive fundamentals rather than red team specifics, closing it first pays off; our CPTS study guide covers the practical pentesting base that CRTO assumes you already have.
Step-by-step: how to prepare for CRTO
The most efficient way to plan how to prepare for CRTO is to structure everything around the exam’s lifecycle and its OPSEC-weighted scoring model rather than around a random reading list.
1. Map the blueprint and pass conditions
Translate the exam into personal objectives. You need a reliable initial access chain, a repeatable lateral movement path, and a documented OPSEC playbook. Keep the pass conditions visible: capture at least six of eight flags and clear roughly 85 of 100 points, with half of that score tied directly to staying quiet.
2. Set timeline, budget, and exam date
Given the 60–120 hour range, pick a schedule you can actually hold. At around 10 hours per week, target a 6–8 week timeline. Budget for the RTO course plus CRTO exam at about £399, plus any supplemental materials. Book the exam only after you have completed at least half the labs and can navigate the environment efficiently.
3. Enroll in Red Team Ops and build a lab routine
Enroll in the official Red Team Ops course, which bundles the material, labs, and exam access, including lifetime access to written and video content and one included attempt. Then structure your week:
- Two to three focused lab sessions (2–4 hours each).
- One reading and note-taking session (1–2 hours).
- One end-to-end “full chain” run every one to two weeks.
Mid-plan is where time-constrained candidates fall behind. If your hours are slipping, our CRTO exam dumps with lab-aligned materials and updated methodology provide curated scenarios, domain-aligned questions, and answer rationales tuned to mirror the current lab ecosystem, delivered instantly to cut trial-and-error study.
4. Build core Cobalt Strike proficiency
CRTO is strongly anchored to Cobalt Strike, so treat it as a primary skill. Work on beacon configuration and profiles (sleep, jitter, indicators), payload delivery through common tradecraft, pivoting and in-memory execution, managing multiple teamsites and listeners for redundancy, and recovering gracefully from unstable endpoints or network drops. Record every reusable profile and procedure in a personal playbook.
5. Master Active Directory attack paths
RTO and CRTO revolve around realistic AD environments. Practice initial access through exposed services, weak credentials, or misconfigurations; credential harvesting via LSASS, DPAPI, Kerberoasting, and NTLM relay; privilege escalation and lateral movement over RDP, WinRM, and SMB; and domain dominance through trust abuse, delegation, and ticket attacks where appropriate. When you can reach domain admin along multiple routes, you are close to technically exam-ready.
6. Practice OPSEC and detection evasion
Because OPSEC carries half the score, make it a first-class part of every session. Prefer low-and-slow beacon configurations, cache recon results instead of rerunning noisy enumeration, lean on trusted tools and LOLBins, and watch the lab’s logs and alerts as a defender would. In your notes, flag high-risk actions and pre-plan quieter alternatives.
7. Run full simulated engagements
Once fundamentals are stable, rehearse complete engagements: plan objectives and constraints, execute from initial access to domain compromise, track a timeline of actions and artifacts, then review what would have triggered detection. These rehearsals closely mirror the exam’s four-day rhythm.
8. Refine note-taking and self-documentation
CRTO requires no formal report, but disciplined notes still decide outcomes. Build reusable command snippets, maintain a map of AD entities and relationships, and track credentials, hashes, tickets, and access points clearly so you can backtrack quickly and confirm you captured every flag.
9. Design a personal exam strategy
Plan the 48 hours like an endurance event. Choose a four-day window you can protect, decide how to split the time (for example, roughly 12 focused hours per day), and set checkpoints such as “initial foothold and two flags by hour 12.” Schedule sleep, breaks, and food so fatigue does not quietly cost you flags or OPSEC points.
10. Final week: light review and targeted sprints
In the last week, review your notes and OPSEC checklist, run two or three short sprints on weak spots like Kerberoasting or constrained delegation, and refine what you already know instead of learning new tools. If it becomes clear you will not realistically reach 60–120 hours before your date, mentor-supported CRTO materials can close the gap by focusing you on the most exam-relevant paths.
Common mistakes and how to fix them
- Relying only on pentesting experience. Shift toward long-term adversary simulation and persistence; practice staying resident and undetected, not just proving exploitability.
- Treating Cobalt Strike as a black box. Learn beacon profiles, listeners, and jitter deliberately instead of running defaults.
- Neglecting AD fundamentals. Revisit domain trusts, Kerberos, and delegation before attempting sophisticated chains.
- Underestimating OPSEC. Build an OPSEC checklist and run it during every lab; avoid noisy recon and aggressive scanning.
- Poor exam time management. Pre-plan milestones and hold them; do not chase low-value flags that threaten your main objective or OPSEC score.
- Sparse, disorganized notes. Standardize templates for commands, findings, credentials, and attack paths, and rehearse using them in the labs.
DIY versus mentor-supported prep
A pure DIY path works when you already have solid AD and Cobalt Strike experience, can commit the full 60–120 hours across several weeks, and genuinely enjoy self-paced experimentation. In that case the official course alone can carry you to a pass.
Mentor-supported, accelerated prep fits a different profile: time-constrained IT and security professionals who need to pass quickly, newcomers to red teaming who want a structured scenario-driven path, and candidates who prefer guided coverage of common exam domains, typical flag paths, and current methodology. We position our CRTO offerings for this second group, with instant-delivery materials, lab-aligned scenarios, mentor support, and a success-focused methodology built to compress study time while keeping practical understanding intact. Added to the official Red Team Ops course, our CRTO preparation materials can turn a vague “someday” into a scheduled, realistic pass date.
So make the call explicitly. Weeks of free time and strong fundamentals point toward DIY around the official course. Limited time, or a preference for structured guidance and a success guarantee, points toward layering our mentor-supported CRTO resources onto your plan.
CRTO preparation FAQ
How long does it take to prepare for CRTO?
Most professionals report 60–120 hours of study, typically spread over 4–8 weeks, to feel confident across both the technical and OPSEC requirements.
What is the total cost of CRTO?
Common bundles list the Red Team Ops course plus the CRTO exam at about £399, including lifetime access to the course materials, substantial lab time, and at least one exam attempt.
Is a written report required for the CRTO exam?
No. The exam is objective-based; you earn points by achieving goals and capturing flags in the lab rather than submitting a graded report.
How long is the exam and how is it structured?
It provides 48 hours of lab time over four days, structured as a capture-the-flag exercise. Community accounts describe eight flags in total, with six required to pass.
How can I prepare for CRTO with very limited study time?
Pair the official Red Team Ops course with structured, mentor-supported materials that offer lab-aligned question banks and scenario-based practice, so you focus on the most exam-relevant content and reduce guesswork before your date.
