اختبار الأمن السيبراني (CST)
المقدمة

أيقونة اختبار الأمن السيبراني

أهداف اختبار الأمن السيبراني

تقييم المعرفة والمهارات
ومستوى الكفاءة

تقييم نظري وعملي

اختبار CST هو امتحان يتكوّن من جزأين، ويركّز على المعرفة وتطبيق المهارات في سيناريوهات ومشكلات مختلفة.

تحديد مستوى القدرات الحالية
في مجالات الأمن السيبراني

التخصصات الأساسية في الأمن السيبراني

يتم تقييم كل مرشح عبر مجالات الأمن السيبراني. ويقيس كل مجال مستوى المرشحين باستخدام أسئلة مقسّمة إلى 3 مستويات.

تحديد فئات المواهب
بناءً على الأداء العام

تحليل النتائج

يتم منح المرشحين درجات وفق نظام يساعد على تحليل النتائج وتصنيفهم ضمن فئات مواهب مختلفة.

تقديم رؤى قائمة على البيانات
لدعم تقديم التدريب

خط أساس لمهارات الأمن السيبراني

يوفّر اختبار CST خط أساس بسيطاً للحالة الحالية للقدرات السيبرانية، لدعم تحديد متطلبات التدريب وبناء القدرات السيبرانية مستقبلاً.

Domains Covered in CST | Topics

Cybersecurity
Foundation

  • Secure system design principles and resilience
  • Data protection fundamentals: encryption, PII safeguarding, and access control
  • Operating system security: permissions, resource management, and monitoring
  • Network and endpoint security basics: firewalls, DDoS detection, and host-based controls

Digital Forensics

  • Incident detection, triage, and escalation processes
  • Evidence preservation and chain-of-custody best practices
  • Memory and disk imaging, file carving, and metadata analysis
  • Malware analysis and rootkit detection
  • Use of SIEM tools and application of MITRE ATT&CK framework

Cybersecurity Threat
& Intelligence

  • Threat intelligence validation and operationalization
  • Threat actor profiling and Tactics, Techniques, and Procedures (TTPs)
  • Use of network telemetry (DNS, TLS, passive DNS) and geospatial data for hunting
  • Insider threat and lateral movement detection

Security Architecture

  • Network segmentation and cross-domain data flow control
  • Secure remote access and vendor management
  • Cryptographic controls and key management policies
  • Business continuity, disaster recovery, and supply-chain risk management

Vulnerability
Management

  • Vulnerability scanning, prioritization, and remediation
  • Privilege escalation detection and mitigation
  • Secure coding practices and authentication automation
  • Compliance with cybersecurity regulations and standards

Industrial Control
Systems and
Operational Technology

  • ICS/OT network segmentation and protocol security (Modbus/TCP, OPC-UA)
  • Vendor remote access and firmware update controls with multi-factor authentication
  • Incident response and evidence preservation specific to ICS/OT environments
  • Balancing operational continuity with security and regulatory compliance

Governance, Risk
and Compliance

  • Translating regulatory requirements into actionable policies and controls
  • Risk assessment, prioritization, and mitigation aligned with mission objectives
  • Incident reporting, audit trail management, and compliance monitoring
  • Vendor and supply-chain risk management

Security Operations

  • Security event monitoring and alert triage processes
  • SIEM deployment, configuration, and advanced log correlation techniques
  • Endpoint Detection and Response (EDR) tool usage and telemetry analysis
  • Network traffic analysis specific to SOC (NetFlow, DNS, packet captures)

Cyber Research and
Development

  • Emerging cybersecurity technologies
  • Secure software/system development lifecycle
  • Threat detection research methods
  • AI and machine learning applications
  • Industry-academia collaboration
  • Tool evaluation and validation

Cybersecurity
Workforce
Management

  • Skills gap and workforce planning
  • Recruitment and training
  • Competency frameworks and certifications
  • Employee retention and security culture
  • Insider threat management
  • Workforce performance metrics

Cybersecurity
Leadership

  • Cybersecurity governance and policy
  • Executive risk management
  • Leading cybersecurity teams
  • Communicating risks to stakeholders
  • Incident response leadership
  • Aligning security with business goals

CST Guidelines

The assessment is not an open-book assessment; therefore, the use of external materials, references, or electronic devices is not allowed

Collaboration, communication, or sharing information with other participants during the assessment is not permitted

Participants are expected to adhere to the allocated time for completing the assessment

The assessment must be carried out individually, and participants are expected to rely solely on their own knowledge and judgment

Maintaining the integrity and confidentiality of the assessment content is required at all times

Participants are expected to follow all assessment guidelines throughout the assessment process

Test Components and Duration

1|Theoretical Evaluation

Brief

A set of multiple-choice questions that assess basic cyber knowledge and skills.

 

Number of Questions

105 - 135 Theoretical Questions

 

Duration

120 - 150 minutes

2|Practical Evaluation

Brief

A set of practical scenarios assesses the practical application of skills and behaviors.

 

Number of Questions

30 - 42 Practical Questions

 

Duration

150 - 180 minutes

CST Components & Methods

Theoretical Foundation/
Theoretical Domain

Multiple Choice Short
Questions

Practical Domain

Environment Labs (Capture the
Flag (CTF) Simulation Based)

Practical Domain - Novel

  • Scenario Based
  • Case Studies (Qualitative)
  • Dashboard/Tool Analysis Cases
  • Data Analysis Cases
آخر تعديل: الجمعة، 31 يوليو 2026، 2:08 PM
هذا موقع غير إنتاجي