2026年にCREST Certified Red Team Manager - Multiple Choice Long Formへ挑戦するなら、再受験にかかる費用負担はできるだけ避けたいところです。Tech4ExamのCCRTM-MCLF練習問題で本番形式の問い方に慣れておけば、一度で結果を出すための土台づくりが進みます。
CREST CCRTM-MCLF 試験概要:
| 認定ベンダー: | CREST |
|---|---|
| 試験名: | CREST Certified Red Team Manager - Multiple Choice Long Form |
| 試験番号: | CCRTM-MCLF |
| 受験料: | £800 + VAT |
| 認定の有効期間: | 3年 |
| 対応言語: | 英語 |
| 試験形式: | 選択式問題, 記述式問題 |
| 合格点: | 個別の選択式・記述式試験について、CRESTによる合格基準は公表されていません |
| 試験時間: | 180 分 |
| 関連資格: | CREST Certified Red Team Manager (CCRTM) |
| サンプル問題: | DOWNLOAD DEMO |
| 受験方法: | Pearson VUEテストセンターで実施されます。選択式・記述式試験の所要時間は3時間(選択式1時間、それに続く記述式2時間)で、記述式セクションの前に15分間の事前確認時間(リーディングタイム)が設けられています。試験はクローズドブック(資料持ち込み不可)形式です。 |
| 前提条件: | CCRTMを受験するための独立した前提資格試験はCRESTによって設定されていません。本認定では、広範なレッドチーム知識に加え、インシデントやリスクの管理、ペネトレーションテスト、攻撃シミュレーション演習における確かな実務経験を持つ受験者が評価対象となります。 |
| 公式シラバスのURL: | https://www.crest-approved.org/ccrtm-faqs/ |
CREST CCRTM-MCLF 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: 計画とスコープ定義 | - エンゲージメントにおけるステークホルダー - 要件分析(スコープ定義) |
| トピック 2: 主要な概念 | - レッドチームのフレームワーク - レッドチーム、パープルチームテスト、ペネトレーションテスト - 検知・対応評価 - 攻撃パスのマッピングおよび攻撃パスのシミュレーション - 専門用語 |
| トピック 3: リスクマネジメント、報告およびコミュニケーション | - 国際的に認知された標準およびフレームワーク - エンゲージメントのリスクマネジメント - リスクの明確化と説明 - 専門用語集 |
| トピック 4: 攻撃マネジメントにおける法的・倫理的・道徳的側面 | - 意図しないターゲット設定および付随的ターゲット設定 - コンピュータ犯罪/サイバー不正利用および誤用に関する法令 - その他の関連法令または契約上の情報 - プライバシー関連法令 - データ取扱いに関する法令 - 倫理的なテストにおける考慮事項 |
| トピック 5: 攻撃手法、主要フェーズおよび一般的なフレームワーク | - ハイブリッド環境のテストとリスク - 横展開(Lateral Movement)の手法とリスク - 攻撃手法フレームワーク - クラウド環境のテストとリスク - 権限昇格(Privilege Escalation)の手法とリスク - 永続化(Persistence)の手法とリスク - 物理アクセス制御のバイパス手法とリスク - 初期アクセス(Initial Access)の手法とリスク |
| トピック 6: スレットインテリジェンス(脅威インテリジェンス) | - 脅威モデルの検討事項 - 脅威インテリジェンスの情報源 - 脅威インテリジェンス情報源における法的・倫理的考慮事項 - アクティブ手法とパッシブ手法の利点比較 |
| トピック 7: エンゲージメントの規則(Rules of Engagement)、緊急対応およびシナリオシミュレーション | - エンゲージメントの規則(Rules of Engagement) - 緊急対応(コンティンジェンシー)/クライアント支援 - テスト計画 - シナリオの種類 |
| トピック 8: プロジェクトマネジメント、ガバナンスおよび監督 | - コミュニケーション計画 - ステークホルダー管理とエンゲージメントの整合性・信頼性 - レッドチームエンゲージメントのフェーズ - コントロールグループの役割と責任 - インシデント管理対応 |
| トピック 9: Dropper/Implant設計、安全性およびセキュアコーディング | - インフラストラクチャ制御 - Implant制御 - 永続的(Persistent) vs 半永続的(Semi-Persistent)Implant設計とリスク - Implant Dropperの機能とリスク - セキュアなデータ取扱い - Implantのコア機能とリスク - 暗号化 vs エンコーディング |
CCRTM-MCLFに挑戦する方へ – よくある質問まとめ
CCRTM-MCLF試験はCREST Certified Red Team Manager - Multiple Choice Long Formの公式認定試験で、合格するとCREST Certifiedの認定を取得できます。この認定はCertifiedレベルに位置づけられています。関連する認定には、CREST Certified Red Team Manager (CCRTM)などがあります。Tech4Examでは、この試験の出題傾向に沿った304問の練習問題をご用意しています。
CCRTM-MCLF試験の合格ラインは個別の選択式・記述式試験について、CRESTによる合格基準は公表されていません、受験料は£800 + VATです。不合格になった場合、再受験には改めて全額の受験料が必要になるため、一度の受験で合格ラインをクリアできる準備が費用面でも重要です。Tech4Examの304問の練習問題で繰り返し自己採点を行い、安定して合格点を上回れることを確認してから本番に臨むと安心です。
受験条件は見直される場合があります。お申し込みの前に、CRESTの公式ページで最新の情報をご確認ください。
はい、Tech4ExamではCCRTM-MCLF練習問題の無料サンプルをご用意しています。304問の問題集の一部を事前にご確認いただけるので、内容や品質に納得してからご購入いただけます。ご購入後は365日間の無料アップデートが付き、期間終了後も50%割引で更新を継続いただけるため、常に最新の出題内容に沿って学習できます。
Tech4Examには返金保証があります。ご購入後60日以内に対応する試験を受験して不合格だった場合、全額返金をお申し込みいただけます。ただし、購入後3日以内の受験による不合格、ダウンロード後に実際の試験を受験しなかった場合、無料資料や有効期限切れのご注文は対象外となり、受験者の氏名はお支払い者の氏名と一致している必要があります。お申し込みの際は、受験票のコピーと公式のScore ReportのPDFを試験後2日以内にご提出ください。提出後7日以内に手続きが完了します。返金の代わりに、同等の試験資料2点を無料でお受け取りいただき、お手持ちの製品の更新サービスをそのまま継続する選択も可能です。納品は即時ダウンロード方式で、お支払い完了後1分以内にメールでお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールするパソコンの台数に制限はありません。
CCRTM-MCLF試験の出題範囲は9の領域に分かれています。主な領域として、「計画とスコープ定義」、「攻撃手法、主要フェーズおよび一般的なフレームワーク」、「主要な概念」などが挙げられます。各領域の詳しい内訳については、このページ上部に掲載している試験シラバスをご確認ください。
CREST Certified Red Team Manager - Multiple Choice Long Form 認定 CCRTM-MCLF 試験問題:
Which piece of UK legislation is most directly relevant to how personal data encountered or processed during a red team engagement must be handled?
- A. The Computer Misuse Act 1990
- B. The Companies Act 2006
- C. The Bribery Act 2010
- D. UK GDPR and the Data Protection Act 2018
解説: (Tech4Exam メンバーにのみ表示されます)
Which of the following best describes the practical value of the "family resemblance" among CBEST, TIBER- EU, iCAST, CORIE, AASE, STAR/STAR-FS and GBEST for a Red Team Manager building internal delivery capability?
- A. It means all schemes require completely separate, non-transferable staff, tooling, and processes
- B. It implies only one scheme needs to be learned, and the rest can be safely ignored
- C. It has no practical relevance to internal capability planning
- D. It allows the manager to build a single core methodology, governance approach and skill set that can then be adapted with jurisdiction- and scheme-specific detail, rather than building entirely separate capabilities from scratch for each scheme
解説: (Tech4Exam メンバーにのみ表示されます)
Which of the following best describes the risk of "confirmation bias" in threat intelligence analysis supporting a red team engagement?
- A. Confirmation bias has no relevance to threat intelligence analysis
- B. Analysts may unconsciously favour information that confirms a pre-existing assumption about the likely threat actor or scenario, potentially resulting in a less accurate, less genuinely plausible assessment - good analytical discipline (e.g., structured analytic techniques, peer review) helps mitigate this
- C. Confirmation bias can be entirely eliminated through the use of automated tools alone
- D. Confirmation bias only affects junior analysts, never experienced ones
解説: (Tech4Exam メンバーにのみ表示されます)
Which of the following statements about "safe words" or coded phrases sometimes used in physical/social engineering engagements is most accurate?
- A. Safe words are only relevant to technical (not physical) testing
- B. Safe words have no legitimate use in professional engagements
- C. A pre-agreed safe word or phrase can allow a tester, if directly challenged or in a difficult situation during physical/social engineering activity, to discreetly verify their authorised status to a designated client contact without fully breaking the test's cover inappropriately or escalating unnecessarily
- D. Safe words replace the need for any written authorisation
解説: (Tech4Exam メンバーにのみ表示されます)
Which of the following best describes the relationship between good red team management practice and the frameworks discussed elsewhere in this document (CBEST, TIBER-EU, iCAST, and related schemes)?
- A. Good management practice is only relevant to engagements delivered outside any named framework
- B. Management practice is entirely separate from framework compliance and has no bearing on it
- C. Strong underlying management practice (resourcing, risk management, governance discipline, quality assurance) is what actually enables an engagement to meet the detailed requirements of frameworks like CBEST, TIBER-EU, or iCAST in practice, not merely on paper
- D. Frameworks like CBEST and TIBER-EU explicitly prohibit conventional project management practices
解説: (Tech4Exam メンバーにのみ表示されます)

弊社は製品に自信を持っており、面倒な製品を提供していません。


-鹿野**

