CREST CCRTM-MCLF Exam Overview:
| Certification Vendor: | CREST |
|---|---|
| Exam Name: | CREST Certified Red Team Manager - Multiple Choice Long Form |
| Exam Number: | CCRTM-MCLF |
| Related Certifications: | CREST Certified Red Team Manager (CCRTM) |
| Exam Duration: | 180 minutes |
| Available Languages: | English |
| Exam Format: | Long Form, Multiple Choice |
| Certificate Validity Period: | 3 years |
| Exam Price: | £800 + VAT |
| Recommended Training: | CREST Training Provider Search |
| Exam Registration: | Pearson VUE - CREST Exam Registration |
| Sample Questions: | CREST CCRTM-MCLF Sample Questions |
| Exam Way: | Pearson VUE test centres. The Multiple Choice & Long Form examination lasts 3 hours in total: 1 hour for the multiple-choice component and 2 hours for the long-form component, with an additional 15 minutes of reading time before the long-form component. The exam is closed book. |
| Pre Condition: | No formal prerequisite exam is stated by CREST. The certification is an advanced-level qualification intended for candidates with relevant red team knowledge and experience in managing incidents, risks, penetration tests and simulated attack exercises. |
| Official Syllabus URL: | https://www.crest-approved.org/wp-content/uploads/2025/05/CREST-Certified-Red-Team-Manager-Technical-Syllabus-v2.1.pdf |
CREST CCRTM-MCLF Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Attack Methodology, Key Stages & Common Frameworks | - Privilege Escalation Techniques and Risks - Initial Access Techniques and Risks - Attack Methodology Frameworks - Cloud Environment Testing and Risks - Persistence Techniques and Risks - Lateral Movement Techniques and Risks - Physical access control bypasses and risks - Hybrid Environment Testing and Risks |
| Dropper/Implant Design, Safety and Secure Coding | - Implant Controls - Implant Droppers capabilities and risks - Infrastructure Controls - Secure Data Handling - Implant Core capabilities |
| Threat Intelligence | - Sources of Threat Intelligence - Considerations of Threat models (digital vs Physical) - Benefits of Active vs Passive Methodologies - Legalities / Ethics considerations of Threat Intelligence sources |
| Legal, Ethical and Moral Aspects of Attack Management | - Ethical testing considerations - Inadvertent and Collateral targeting - Privacy legislation - Computer crime/cyber abuse and misuse legislation - Data handling legislation - Additional relevant legislation or contractual information |
| Rules of Engagement, Contingencies and Scenario Simulation | - Contingencies / Client Facilitation - Test plans - Rules of Engagements - Types of scenarios |
| Project Management, Governance & Oversight | - Stakeholder Management & Engagement Integrity - Incident Management Response - Communications plans - Roles & responsibilities of the control group - Stages of a red team engagement |
| Key Concepts | - Red team, Purple team testing, penetration testing - Attack Path Mapping & Attack Path Simulation - Red Team Frameworks - Detection and Response Assessment - Terminology |
| Risk Management, Reporting and Communication | - Engagement Risk Management - Articulating Risk - Internationally Recognised Standards and Frameworks - Lexicon |
| Planning & Scoping | - Requirements Analysis (scoping) - Stakeholders for engagements |
CREST Certified Red Team Manager - Multiple Choice Long Form Sample Questions:
Question 1
Within TIBER-EU governance, who is the single, accountable internal point of contact responsible for managing the test on behalf of the entity?
A. The Blue Team Lead
B. The Threat Intelligence analyst
C. The Control Team Lead (CTL)
D. The national TIBER Cyber Team chair
Question 2
Why is it important for a Red Team Manager to understand multiple regional frameworks even if their firm primarily delivers CBEST engagements?
A. All frameworks are legally interchangeable so no additional understanding is needed
B. Client organisations increasingly operate across borders, and understanding the broader family of frameworks enables the manager to advise accurately on cross-jurisdictional obligations, avoid misapplying one scheme's requirements to another, and support informed, compliant programme design
C. It is not important; expertise in one framework is always sufficient for every client and jurisdiction
D. Understanding other frameworks is purely of academic interest with no commercial relevance
Question 3
Which of the following best captures the relationship between scoping and the overall risk management of a red team engagement?
A. Risk management is solely a technical activity conducted during testing, with no connection to scoping decisions
B. Well-executed scoping is one of the primary mechanisms through which engagement risk is identified, discussed, and proactively managed before testing begins
C. Scoping cannot meaningfully influence risk, since all red team activity carries identical risk regardless of scope
D. Scoping and risk management are entirely separate, unconnected activities
Question 4
Which of the following is the most appropriate way to handle a request to include operational technology (OT) or industrial control systems (ICS) with potential life-safety implications within the scope of a red team engagement?
A. Automatically exclude all OT/ICS systems from every engagement with no further discussion
B. Allow testing to proceed without informing engineering or safety teams, to preserve realism
C. Include them in the same manner and with the same techniques as standard IT systems, with no special consideration
D. Apply significantly enhanced caution - carefully assess whether live testing is appropriate at all, consider safer alternative approaches (e.g., testing in a representative non-production environment, or a more limited, closely supervised assessment), and involve relevant engineering/safety stakeholders in the scoping decision
Question 5
Under the UK's Computer Misuse Act 1990, what is the primary defence available to a red team tester who accesses a computer system as part of an authorised engagement?
A. That the client verbally agreed at some point in the past, regardless of documentation
B. There is no defence available; all access is automatically an offence
C. That the access was authorised by a person entitled to grant such authorisation, meaning it falls outside the definition of "unauthorised access"
D. That the tester is a CREST-certified professional, which grants blanket immunity regardless of authorisation
Solutions:
| Question 1 Answer: C | Question 2 Answer: B | Question 3 Answer: B | Question 4 Answer: D | Question 5 Answer: C |
We're so confident of our products that we provide no hassle product exchange.


By Jack

