In January, I set my self the task of taking the CREST CRT examination. I am glad to say I passed the exam (woohoo). I would say this was a greater challenge than OSCP, or at least versus how I remember the OSCP.
Back when I took took the OSCP in 2019 (I'm getting old), it was definitely annoying having a proctor watching me pick my nose and eating at the machine, but it felt a bit more realistic that I could research as I wanted, and more importantly there was some time for trial and error. With the CREST CRT exam, though you have a syllabus and you have the option to use CRESTDrive to plan ahead, you do not have a crystal ball to know what'll be on there and there is no Internet during the exam, if you haven't got the materials and can't remember the steps... you're going to have a bad time as you don't have much time for trial and error. The other side of this is you can have information overload with too much in CRESTDrive, too many docs telling you similar thing can be a time burner, it's better to try focus what you brush up on around the syllabus and get docs/guides that cover this in CRESTDrive.
Here are my tips for the exam:
Tip 1: Understanding where the marks are and the effort required is very important. Routing manipulation, desktop lockdown, and simple exploitation is worth 60 marks and doesn't have that many questions. Other areas require scanning and won't have information available to you straight away, don't sit trying to grab information as it is spat out at you.
Tip 2: You need 60% on both sections, you can't beef up the result by nailing web and lagging on infra. Make sure you give plenty of time to infra.
Tip 3: CRESTDrive may allow you to upload hacktricks and other hacking bibles, but don't just rely on this, try align materials with the syllabus or you'll have information overload. CRESTDrive also allows for the upload of your own tools which may help with enumeration and exploitation – it doesn't have to just be PDFs and guides.
As a side note, I would strongly recommend not relying on the HTB learning path for this, there are some significant gaps based on what I saw in the exam.
Good luck for anyone planning to take the exam who sees this! It is definitely a worthwhile exam, and I am glad CREST have moved on from the NCC situation to offer a fairer way to assess competency. I wonder how many who need to renew for CHECK try another avenue instead of CREST now it can't be gamed :-).