CREST CCRTM-MCLF Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Planning & Scoping | - Stakeholders for engagements - Requirements Analysis (scoping) |
| Project Management, Governance & Oversight | - Roles & responsibilities of the control group - Stages of a red team engagement - Incident Management Response - Communications plans - Stakeholder Management & Engagement Integrity |
| Risk Management, Reporting and Communication | - Internationally Recognised Standards and Frameworks - Articulating Risk - Lexicon - Engagement Risk Management |
| Rules of Engagement, Contingencies and Scenario Simulation | - Test plans - Rules of Engagements - Contingencies / Client Facilitation - Types of scenarios |
| Legal, Ethical and Moral Aspects of Attack Management | - Additional relevant legislation or contractual information - Computer crime/cyber abuse and misuse legislation - Privacy legislation - Inadvertent and Collateral targeting - Ethical testing considerations - Data handling legislation |
| Attack Methodology, Key Stages & Common Frameworks | - Physical access control bypasses and risks - Lateral Movement Techniques and Risks - Cloud Environment Testing and Risks - Initial Access Techniques and Risks - Hybrid Environment Testing and Risks - Privilege Escalation Techniques and Risks - Attack Methodology Frameworks - Persistence Techniques and Risks |
| Threat Intelligence | - Benefits of Active vs Passive Methodologies - Considerations of Threat models - Sources of Threat Intelligence - Legalities / Ethics considerations of Threat Intelligence sources |
| Key Concepts | - Attack Path Mapping and Attack Path Simulation - Red Team Frameworks - Red team, purple team testing, penetration testing - Terminology - Detection and Response Assessment |
| Dropper/Implant Design, Safety and Secure Coding | - Secure Data Handling - Infrastructure Controls - Persistent vs Semi-Persistent implant design and risks - Implant Droppers capabilities and risks - Encryption vs Encoding - Implant Core capabilities and risks - Implant Controls |
CREST Certified Red Team Manager - Multiple Choice Long Form Sample Questions:
Question #1
A Red Team Manager is designing a proposal referencing "intelligence-led testing" for a prospective client outside the financial sector (e.g., a critical national infrastructure energy provider). Which statement about applicability is most accurate?
A. The underlying intelligence-led methodology (threat intelligence, scenario design, live testing, blind defenders, structured closure) can be adapted to other critical sectors, even where a bespoke named scheme like CBEST does not apply, provided governance and legal considerations are properly addressed for that context
B. Intelligence-led testing principles apply only to banks and can never be adapted to other critical sectors
C. Energy providers are legally barred from any form of red team testing
D. Only government departments may ever commission intelligence-led testing
Question #2
Why might a Data Protection Impact Assessment (DPIA) be advisable before certain red team engagements?
A. Where testing is likely to involve high-risk processing of personal data (for example, targeted social engineering using personal data, or handling of sensitive data encountered during exploitation), a DPIA helps identify and mitigate data protection risks in advance
B. DPIAs are irrelevant to security testing activities
C. A DPIA replaces the need for client authorisation
D. DPIAs are only required for marketing campaigns
Question #3
A client operating only in a jurisdiction with no formally named intelligence-led testing scheme asks whether they can still benefit from this style of assessment. What is the most accurate answer?
A. They must relocate their headquarters to a jurisdiction with a named scheme first
B. Intelligence-led testing is only theoretically possible and has never been delivered outside named schemes
C. Yes; the underlying methodology can be applied on a voluntary, best-practice basis, tailored to the client's actual risk profile and local legal context, even without a formally named local scheme
D. No, intelligence-led testing is legally restricted to jurisdictions with a named scheme
Question #4
Which of the following best describes an appropriate approach to gathering and acting on client feedback following an engagement?
A. Structured feedback should be actively sought from the client, reviewed honestly (including any critical feedback), and used to inform genuine improvement in future engagement planning and delivery
B. Only positive feedback should be recorded and shared internally, with critical feedback discarded
C. Client feedback should never be sought, since it has no bearing on future engagement quality
D. Feedback should only be gathered if the client proactively volunteers it unprompted
Question #5
A Red Team Manager is finalising legal documentation for a first-of-its-kind engagement in a jurisdiction the firm has never operated in before. Which combination of actions best reflects sound legal risk management?
A. Rely solely on the client's own in-house legal team's assurance with no independent verification
B. Commission local legal advice on relevant cybercrime, data protection, and contract law; adapt authorisation, Rules of Engagement, and contractual documentation accordingly; and confirm insurance coverage extends appropriately to the new jurisdiction
C. Proceed using the firm's standard UK-templated documents unchanged, since good methodology is universally applicable
D. Delay indefinitely until a formally named local intelligence-led testing scheme exists in that jurisdiction
Solutions:
| Question #1 Answer: A | Question #2 Answer: A | Question #3 Answer: C | Question #4 Answer: A | Question #5 Answer: B |














0 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
