CREST CCRTM-MCLF Exam Overview:
| Certification Vendor: | CREST |
|---|---|
| Exam Name: | CREST Certified Red Team Manager - Multiple Choice Long Form |
| Exam Number: | CCRTM-MCLF |
| Available Languages: | English |
| Passing Score: | Not publicly specified by CREST for the individual Multiple Choice & Long Form examination |
| Exam Duration: | 180 minutes |
| Exam Price: | £800 + VAT |
| Exam Format: | Long Form Questions, Multiple Choice Questions |
| Certificate Validity Period: | 3 years |
| Related Certifications: | CREST Certified Red Team Manager (CCRTM) |
| Sample Questions: | CREST CCRTM-MCLF Sample Questions |
| Exam Way: | Pearson VUE test centres. The Multiple Choice & Long Form examination lasts 3 hours: 1 hour multiple-choice followed by 2 hours long form, with an additional 15 minutes reading time before the long-form component. The examination is closed book. |
| Pre Condition: | No separate prerequisite examination is stated by CREST for the CCRTM. The certification assesses candidates with broad red-team knowledge and proven experience in managing incidents and risks, penetration tests and simulated attack exercises. |
| Official Syllabus URL: | https://www.crest-approved.org/ccrtm-faqs/ |
CREST CCRTM-MCLF Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Threat Intelligence | - Considerations of Threat models - Sources of Threat Intelligence - Legalities / Ethics considerations of Threat Intelligence sources - Benefits of Active vs Passive Methodologies |
| Topic 2: Attack Methodology, Key Stages & Common Frameworks | - Cloud Environment Testing and Risks - Initial Access Techniques and Risks - Physical access control bypasses and risks - Hybrid Environment Testing and Risks - Attack Methodology Frameworks - Persistence Techniques and Risks - Lateral Movement Techniques and Risks - Privilege Escalation Techniques and Risks |
| Topic 3: Dropper/Implant Design, Safety and Secure Coding | - Implant Core capabilities and risks - Infrastructure Controls - Implant Controls - Secure Data Handling - Encryption vs Encoding - Persistent vs Semi-Persistent implant design and risks - Implant Droppers capabilities and risks |
| Topic 4: Risk Management, Reporting and Communication | - Engagement Risk Management - Internationally Recognised Standards and Frameworks - Articulating Risk - Lexicon |
| Topic 5: Legal, Ethical and Moral Aspects of Attack Management | - Additional relevant legislation or contractual information - Data handling legislation - Privacy legislation - Inadvertent and Collateral targeting - Computer crime/cyber abuse and misuse legislation - Ethical testing considerations |
| Topic 6: Project Management, Governance & Oversight | - Stakeholder Management & Engagement Integrity - Communications plans - Roles & responsibilities of the control group - Incident Management Response - Stages of a red team engagement |
| Topic 7: Key Concepts | - Red team, purple team testing, penetration testing - Detection and Response Assessment - Red Team Frameworks - Attack Path Mapping and Attack Path Simulation - Terminology |
| Topic 8: Rules of Engagement, Contingencies and Scenario Simulation | - Test plans - Contingencies / Client Facilitation - Types of scenarios - Rules of Engagements |
| Topic 9: Planning & Scoping | - Stakeholders for engagements - Requirements Analysis (scoping) |
CREST Certified Red Team Manager - Multiple Choice Long Form Sample Questions:
Which of the following best describes an appropriate approach to client relationship management throughout a lengthy, multi-phase engagement?
- A. Client relationships should be managed reactively, only responding when the client specifically raises a concern
- B. Ongoing, proactive, transparent communication - including realistic expectation-setting, regular updates, and responsiveness to client questions or concerns - helps maintain trust and supports a well- governed, collaborative engagement
- C. Client relationship management is unnecessary once the contract has been signed
- D. Client relationship management should be handled exclusively by a separate sales team, with no involvement from the delivery team
Explanation: Only visible for TopExamCollection members. You can sign-up / login (it's free).
Which of the following is the most appropriate governance approach to managing a potential conflict of interest, such as a Red Team provider also holding a significant ongoing managed security services contract with the same client?
- A. Conflicts of interest only matter for publicly listed companies
- B. Conflicts of interest are irrelevant to red team engagements and never need to be considered
- C. The engagement should always be automatically cancelled the moment any potential conflict is identified, with no further consideration
- D. The potential conflict should be transparently identified, assessed, and appropriately managed (e.g., through disclosure, independent review, or, where necessary, structural separation of teams
/information), to preserve the credibility and independence of the assessment
Explanation: Only visible for TopExamCollection members. You can sign-up / login (it's free).
Which of the following best describes why threat intelligence analysts should clearly distinguish between
"facts," "assessed judgements," and "assumptions" within their analytical products?
- A. Clearly distinguishing these categories helps readers (including the Control Group and Red Team) understand the actual confidence level behind each statement, supporting more informed decision- making about how much weight to place on different elements of the analysis
- B. This distinction has no practical value and is rarely made in professional practice
- C. Assumptions should always be presented with the same confidence as established facts, to avoid confusing the reader
- D. Only facts should ever be included in a threat intelligence report; judgements and assumptions should never be shared
Explanation: Only visible for TopExamCollection members. You can sign-up / login (it's free).
Why might a Red Team Manager advise discreetly informing a national CERT or relevant law enforcement liaison contact in advance of an engagement involving significant physical or overtly suspicious activity?
- A. To reduce the risk of a genuine security or emergency response being triggered and to allow rapid de- escalation and correct attribution of activity to an authorised test, should such a response occur
- B. Because law enforcement must approve every technical detail of the test in advance
- C. Because it transfers full legal responsibility for the test to law enforcement
- D. Because it is a legal requirement for every single engagement without exception
Explanation: Only visible for TopExamCollection members. You can sign-up / login (it's free).
Which of the following is the most accurate statement about how DORA's TLPT requirement interacts with a banking group that also has a UK subsidiary in scope of CBEST?
- A. DORA has no application to any entity with any UK operations whatsoever
- B. Satisfying CBEST in the UK automatically satisfies DORA TLPT obligations for the EU entities with no further action
- C. CBEST automatically ceases to apply once a group has any EU presence
- D. DORA TLPT applies specifically to the EU-domiciled, in-scope entities based on EU regulatory designation, and is distinct from the UK's CBEST regime, which applies separately to the UK entity under Bank of England/PRA/FCA supervision
Explanation: Only visible for TopExamCollection members. You can sign-up / login (it's free).

We're so confident of our products that we provide no hassle product exchange.


By Kyle


