CREST CCRTM-MCLF 試験概要:
| 認定ベンダー: | CREST |
|---|---|
| 試験名: | CREST Certified Red Team Manager - Multiple Choice Long Form |
| 試験番号: | CCRTM-MCLF |
| 出題数: | 択一式問題 約150問 + 記述式問題 1問 |
| 関連資格: | CCRTM-SC (CREST Certified Red Team Manager - シナリオ) CCRTS-P (CREST Certified Red Team Specialist - 実技) CCRTS-MCS (CREST Certified Red Team Specialist - 択一式&シナリオ) |
| 認定の有効期間: | 規定なし |
| 対応言語: | 英語 |
| 受験料: | $850 USD |
| 合格点: | 択一式:40点(3分の2以上)、記述式:80点(3分の2以上)。両セクションの合格が必要です。 |
| 試験時間: | 360 分 |
| 試験形式: | 長文記述式解答, 択一式 |
| 推奨トレーニング: | CREST 推奨トレーニング&対策リソース |
| 受験申し込み: | CREST 公式試験ページ Pearson VUE 受験登録 |
| サンプル問題: | CREST CCRTM-MCLF サンプル問題 |
| 受験方法: | Pearson VUEテストセンターでの現地受験(参照不可のクローズドブック試験) |
| 前提条件: | 必須となる前提条件はありません。ただし、受講者には広範なサイバーセキュリティ知識に加え、特に規制が適用される環境においてレッドチーム演習、ペネトレーションテスト、模擬攻撃演習を主導した経験が求められます。 |
| 公式シラバスのURL: | https://www.crest-approved.org/skills-certifications-careers/crest-certified-red-team-manager/ |
CREST CCRTM-MCLF 試験シラバストピック:
| セクション | 目標 |
|---|---|
| ガバナンス、法務、およびコンプライアンス | - 倫理的かつコンプライアンスに準拠した運用 - 法的フレームワークおよび承認プロセス |
| コミュニケーションとステークホルダー・エンゲージメント | - ステークホルダーの期待値管理 - エグゼクティブへの発見事項の効果的な共有 |
| 脅威インテリジェンスと敵対者シミュレーション | - 脅威インテリジェンスを活用した攻撃シナリオの設計 - MITRE ATT&CKなどのフレームワークへの敵対者戦術のマッピング |
| レッドチームの計画と戦略 | - 目的、スコープ、およびエンゲージメントルールの定義 - 現実的な敵対的シナリオの設計 |
| レッドチームオペレーション管理 | - エンゲージメントの進行状況監視と安全性確保 - チームの連携とアクティビティ管理 |
| リスク管理とレポーティング | - ステークホルダーへの実用的なレポートの提供 - エンゲージメント中のリスク特定 |
CREST Certified Red Team Manager - Multiple Choice Long Form 認定 CCRTM-MCLF 試験問題:
問題 #1
Which of the following best describes the legal significance of a well-defined "chain of custody" process for evidence gathered during a red team engagement?
A. Chain of custody is only relevant to criminal police investigations, never to red team engagements
B. A clear chain of custody helps demonstrate the integrity and provenance of evidence, which can be important if findings are later relied upon in a legal, regulatory, or disciplinary context
C. Chain of custody has no legal significance in this context
D. Chain of custody exists purely to satisfy internal quality assurance, with no external relevance
問題 #2
An AI's Control Group discovers mid-engagement that the iCAST Red Team's actions are about to affect a shared, multi-tenant data centre environment used by other unrelated institutions. What is the most appropriate response?
A. Cancel the AI's banking licence
B. Pause and escalate, ensuring any action affecting shared, multi-tenant infrastructure is properly authorised (including consent from the data centre operator and consideration of impact on other tenants) before continuing
C. Immediately inform the other tenants' customers directly
D. Proceed without pausing, since the AI authorised its own test
問題 #3
Which of the following best describes the purpose of a liability/indemnity clause in a red team engagement contract?
A. To guarantee the provider will never make a mistake
B. To transfer all criminal liability from the provider's staff to the client automatically
C. To eliminate all legal risk for both parties entirely
D. To allocate responsibility and financial risk between the provider and client for defined categories of loss or damage that might arise from the engagement, within agreed limits
問題 #4
Which of the following best describes the purpose of maintaining and periodically updating internal methodology and knowledge management resources within a red team practice?
A. Methodology documentation has no practical benefit and is rarely maintained in professional practice
B. Knowledge management is solely the concern of very large, multinational providers, irrelevant to smaller practices
C. Well-maintained methodology and knowledge resources support consistent quality, help onboard and train staff effectively, and ensure the practice's approach evolves to reflect current threat intelligence, techniques, and lessons learned
D. Methodology documentation should never be updated once initially created, to preserve consistency
問題 #5
Why is "deconfliction" with other concurrent security activities (e.g., a separate vulnerability scanning programme, or another vendor's assessment) an important RoE consideration?
A. Without deconfliction, overlapping activity could cause confusion (e.g., misattributing real vs simulated attack activity), duplicate effort, or unintended interference between different assessment activities
B. Deconfliction is solely the client's responsibility, with no input needed from the Red Team
C. Deconfliction is only relevant to physical, not technical, engagements
D. Deconfliction is unnecessary since concurrent activities never interact with each other
解説:
| 問題 #1 正解: B | 問題 #2 正解: B | 問題 #3 正解: D | 問題 #4 正解: C | 問題 #5 正解: A |














0 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
