CREST Certified Red Team Manager - Scenarioは出題範囲が広く、独学だけでは論点の取りこぼしが起きがちな試験です。Tech4Examが用意するCCRTM-SC向けの20問の問題集は、本試験の傾向を踏まえて構成されており、苦手分野を的確に洗い出せます。
CREST CCRTM-SC 試験概要:
| 認定ベンダー: | CREST |
|---|---|
| 試験名: | CREST Certified Red Team Manager - シナリオ |
| 試験番号: | CCRTM-SC |
| 出題数: | 公開されていません |
| 関連資格: | CREST Certified Red Team Manager (CCRTM) |
| 受験料: | £800 + VAT |
| 試験時間: | 195 分 |
| 合格点: | シナリオ部門の合格点はCRESTにより公開されていません |
| 対応言語: | 英語 |
| 認定の有効期間: | 受験日から3年間 |
| 試験形式: | 記述式シナリオ, シナリオベースの設問 |
| 受験申し込み: | Pearson VUE CREST認定資格の価格および予約 |
| サンプル問題: | DOWNLOAD DEMO |
| 受験方法: | Pearson VUEテストセンターにて実施されます。CCRTMシナリオは記述式シナリオ試験です。試験時間は3時間で、試験開始前に15分間の読解時間が設けられています。 |
| 前提条件: | CRESTはCCRTM試験に対して前提条件を定めていません。CCRTM資格は、「多肢選択式・長文記述式」と「シナリオ」の2つの部門で構成されており、それぞれ個別に予約する必要があります。両部門に合格することが求められます。 |
| 公式シラバスのURL: | https://www.crest-approved.org/ccrtm-faqs/ |
CREST CCRTM-SC 試験シラバストピック:
| セクション | 目標 |
|---|---|
| 攻撃手法、主要段階および一般的なフレームワーク | - 永続化技術とリスク - 攻撃手法フレームワーク - 物理的アクセス制御の回避とリスク - 初期アクセス技術とリスク - 権限昇格技術とリスク - クラウド環境テストとリスク - ハイブリッド環境テストとリスク - ラテラルムーブメント技術とリスク |
| 攻撃管理における法的・倫理的・道徳的側面 | - コンピュータ犯罪、サイバー不正使用および悪用に関する法律 - プライバシーに関する法律 - データ取り扱いに関する法律 - その他の関連法律および契約情報 - 倫理的テストに関する考慮事項 - 意図しない標的設定および付随的標的設定 |
| 交戦規則、緊急時対応およびシナリオシミュレーション | - テスト計画 - 緊急時対応とクライアント支援 - 交戦規則 - シナリオの種類 |
| 脅威インテリジェンス | - 脅威インテリジェンスの情報源 - 脅威モデル - 能動的手法と受動的手法の利点 - 脅威インテリジェンス情報源に関する法的・倫理的考慮事項 |
| リスク管理、報告およびコミュニケーション | - リスク管理用語集 - 国際的に認められた標準とフレームワーク - リスクの明確化 - エンゲージメントリスク管理 |
| 計画とスコーピング | - 要件分析とスコーピング - エンゲージメントのステークホルダー |
| 主要概念 | - 用語 - 検出・対応評価 - 攻撃パスマッピングおよび攻撃パスシミュレーション - レッドチームフレームワーク - レッドチーム、パープルチームテストおよびペネトレーションテスト |
| ドロッパー・インプラント設計、安全性およびセキュアコーディング | - 永続型と半永続型インプラント設計とリスク - インプラントのコア機能とリスク - インフラストラクチャ制御 - インプラント制御 - 暗号化とエンコーディング - インプラントドロッパーの機能とリスク - セキュアなデータ取り扱い |
| プロジェクト管理、ガバナンスおよび監督 | - ステークホルダー管理とエンゲージメントの完全性 - コミュニケーション計画 - コントロールグループの役割と責任 - インシデント管理対応 - レッドチームエンゲージメントの各段階 |
CCRTM-SCに挑戦する方へ – よくある質問まとめ
CCRTM-SC試験はCREST Certified Red Team Manager - Scenarioの公式認定試験で、合格するとCREST Certified Red Team Manager (CCRTM)の認定を取得できます。この認定は認定レベルに位置づけられています。関連する認定には、CREST Certified Red Team Manager (CCRTM)などがあります。Tech4Examでは、この試験の出題傾向に沿った20問の練習問題をご用意しています。
CCRTM-SC試験の出題数は公開されていません、制限時間は195 分です。出題数に対して使える時間は限られるため、1問あたりにかけられるペースを意識しながら解き進める必要があります。難問に時間を使いすぎず、確実に答えられる問題から拾っていく時間配分が得点を安定させる鍵になります。Tech4Examのテストエンジンで制限時間つきの模擬試験を繰り返し、本番と同じリズムで解く感覚を身につけておくことをおすすめします。
CCRTM-SC試験の合格ラインはシナリオ部門の合格点はCRESTにより公開されていません、受験料は£800 + VATです。不合格になった場合、再受験には改めて全額の受験料が必要になるため、一度の受験で合格ラインをクリアできる準備が費用面でも重要です。Tech4Examの20問の練習問題で繰り返し自己採点を行い、安定して合格点を上回れることを確認してから本番に臨むと安心です。
受験条件は見直される場合があります。お申し込みの前に、CRESTの公式ページで最新の情報をご確認ください。
CCRTM-SC試験は、以下の公式窓口からお申し込みいただけます。
試験方式については、Pearson VUEテストセンターにて実施されます。CCRTMシナリオは記述式シナリオ試験です。試験時間は3時間で、試験開始前に15分間の読解時間が設けられています。
はい、Tech4ExamではCCRTM-SC練習問題の無料サンプルをご用意しています。20問の問題集の一部を事前にご確認いただけるので、内容や品質に納得してからご購入いただけます。ご購入後は365日間の無料アップデートが付き、期間終了後も50%割引で更新を継続いただけるため、常に最新の出題内容に沿って学習できます。
Tech4Examには返金保証があります。ご購入後60日以内に対応する試験を受験して不合格だった場合、全額返金をお申し込みいただけます。ただし、購入後3日以内の受験による不合格、ダウンロード後に実際の試験を受験しなかった場合、無料資料や有効期限切れのご注文は対象外となり、受験者の氏名はお支払い者の氏名と一致している必要があります。お申し込みの際は、受験票のコピーと公式のScore ReportのPDFを試験後2日以内にご提出ください。提出後7日以内に手続きが完了します。返金の代わりに、同等の試験資料2点を無料でお受け取りいただき、お手持ちの製品の更新サービスをそのまま継続する選択も可能です。納品は即時ダウンロード方式で、お支払い完了後1分以内にメールでお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールするパソコンの台数に制限はありません。
CCRTM-SC試験の出題範囲は9の領域に分かれています。主な領域として、「攻撃手法、主要段階および一般的なフレームワーク」、「交戦規則、緊急時対応およびシナリオシミュレーション」、「脅威インテリジェンス」などが挙げられます。各領域の詳しい内訳については、このページ上部に掲載している試験シラバスをご確認ください。
CREST Certified Red Team Manager - Scenario 認定 CCRTM-SC 試験問題:
Background: You are the Red Team Manager on a CBEST engagement for Fenwick and Colne Bank. In the Closure phase, your team's detailed activity logs show that a specific technique - exploitation of a misconfigured internal API to extract a sample of authentication tokens - was successfully executed and went entirely undetected by the Blue Team throughout the six weeks of active testing. During the purple team replay session, when this specific finding is presented, the Head of Security Operations (a Blue Team member, now informed as part of Closure) becomes visibly defensive, states that "this API isn't even properly in our monitoring scope, so it's not a fair test," and requests that this specific finding be removed from the final Red Team Test Report because it "doesn't reflect a real gap, just an unfair technicality." Separately, your own internal review confirms the API in question was genuinely within the agreed CBEST technical scope throughout the engagement, and was reachable via a legitimately compromised, in-scope host using an authorised technique.
Question: How should you respond to the Head of Security Operations' request to remove the finding from the report, and what does this scenario illustrate about the purpose and proper handling of purple team replay sessions and final reporting integrity?
See The answer in Explanation part below.
Explanation:
Step 1 - Verify the facts before responding substantively. You have already confirmed (per the scenario) that the API was genuinely within agreed scope and was reached via a properly authorised technique from a legitimately compromised, in-scope host - this is an important first check, since if the finding genuinely had been out of scope, that would be a different, legitimate scope-boundary discussion. Given the facts are confirmed, the finding is legitimate and properly within scope.
Step 2 - Do not agree to remove a genuine, properly evidenced finding from the report. As established throughout this syllabus, objectivity and completeness in reporting are core professional obligations: findings must be reported based on genuine evidence and sound analysis, not adjusted or removed to spare a stakeholder's discomfort, however understandable that discomfort is. Removing a real, in-scope, properly evidenced detection gap because a Blue Team stakeholder finds it uncomfortable or feels it reflects poorly on their team would be a serious breach of reporting integrity and would directly deprive the organisation (and its board/regulator) of accurate, actionable insight into a genuine resilience gap - precisely the opposite of the exercise's purpose.
Step 3 - Engage constructively and empathetically with the underlying concern, without compromising the finding. The Head of Security Operations' defensiveness is a natural, human reaction and should be handled with empathy and professionalism, not dismissed harshly. You should acknowledge the discomfort directly, and constructively probe the substance of their objection: is the concern genuinely about scope (already addressed and resolved in Step 1), or is it really about monitoring coverage decisions that were made by the organisation itself (e.g., a prior decision not to include this API in monitoring scope) - which, if true, actually reinforces rather than undermines the finding's value, since it reveals a genuine, real-world monitoring coverage gap the organisation itself created and needs to know about.
Step 4 - Reframe the finding constructively, using the purple team session's real purpose. This is exactly the situation the purple team/replay session exists to work through collaboratively and non-punitively, as established in the syllabus: rather than a blame exercise, it should be used to jointly and constructively explore why the API was not in monitoring scope, whether that was a deliberate, risk-accepted decision or an oversight, and what a realistic, prioritised remediation path looks like - reframing the finding as a valuable, actionable input rather than a personal criticism of the Head of Security Operations or their team.
Step 5 - Maintain report objectivity while ensuring proportionate context is included. The finding should remain in the report, accurately described, with an appropriately assessed risk rating reflecting genuine business impact - but the report can, and should, include fair, accurate context (for example, factually noting the API's actual monitoring status at the time of testing, if relevant to understanding the finding) without this context being used to minimise, remove, or soften an accurate description of what actually happened.
Accuracy and fairness are not in tension here: an honest, complete, well-contextualised finding serves everyone's interests better than either an inflated or an artificially removed one.
Step 6 - Escalate if the request persists beyond a reasonable professional conversation. If the Head of Security Operations continues to insist on removal after this constructive discussion, this should be raised transparently with the Control Group, since a request to alter or remove a genuine, evidenced finding from a CBEST report is a serious integrity matter that the Control Group (not an individual Blue Team stakeholder, however senior within their own function) has the right and responsibility to be aware of and ultimately decide how to handle, consistent with this syllabus's repeated emphasis on escalating significant governance and integrity issues through the proper channel rather than resolving them informally or unilaterally.
Step 7 - Draw out the broader lesson about purple team sessions and reporting integrity. This scenario illustrates that purple team replay sessions are inherently sensitive because they can surface uncomfortable, personally or professionally difficult findings for defenders, and that maintaining strict reporting objectivity and integrity - while still handling the human dynamics with genuine empathy and constructive framing - is essential to the whole exercise retaining real value. A red team practice, and its individual Red Team Managers, must be willing to hold this line professionally even under direct, senior stakeholder pressure to soften or remove a genuine finding.
Conclusion: The finding is genuine, properly in scope, and correctly evidenced, and should remain accurately reported in the final Red Team Test Report; the Head of Security Operations' discomfort should be handled empathetically and constructively through the purple team process (potentially revealing a genuine, valuable underlying monitoring-scope decision worth surfacing), but this must not extend to removing or softening an accurate finding, and any persistent pressure to do so should be escalated transparently to the Control Group.
---
Background: You are the Red Team Manager for a 12-week TIBER-EU-aligned engagement. In week 7, your firm wins a large, unrelated new contract that your firm's leadership is keen to staff quickly, and you are asked by your own Practice Director to release your firm's second-most-senior consultant on the current engagement
- who has been leading the more technically complex of two parallel attack paths - to begin work on the new contract "part-time, starting Monday, just two days a week for now," while remaining nominally on the TIBER-EU engagement the other three days.
The consultant in question tells you privately that they do not believe they can properly context-switch between a slow-paced, patient, intelligence-led campaign requiring sustained situational awareness of a live target environment, and a fast-moving new client kickoff, without a real risk of errors or missed detail on one or both engagements. Separately, the client's Control Team Lead has no visibility yet of this proposed change and has previously stressed how much they value consistency of personnel on such a sensitive, lengthy engagement.
Question: As Red Team Manager, how would you handle this internal resourcing request from your own firm's leadership, balancing your firm's commercial interests against your professional obligations on the current TIBER-EU engagement? Explain your reasoning and the steps you would take.
See The answer in Explanation part below.
Explanation:
Step 1 - Take the consultant's own professional judgement seriously. The consultant's concern about the cognitive and quality risk of context-switching between a patient, sustained intelligence-led campaign and a fast-moving new engagement is a genuine, well-founded professional concern, directly consistent with the syllabus's treatment of resourcing, wellbeing, and the connection between sustained focus/reduced fragmentation and the quality and safety of live testing decisions. This should not be dismissed as reluctance or waved away by organisational hierarchy - it is exactly the kind of frontline risk signal a responsible Red Team Manager should weigh heavily.
Step 2 - Assess the genuine impact on the current engagement before agreeing to anything. Before responding to your Practice Director, you should concretely assess: how central this consultant's continued, undivided attention actually is to the remaining, more technically complex attack path; whether a reduced, split-attention arrangement could realistically maintain the standard of care and situational awareness the engagement requires (particularly given TIBER-EU's emphasis on sustained, patient, low-and-slow activity, which the syllabus notes a compressed or fragmented tempo can undermine); and whether any other resourcing option exists (e.g., a different, less centrally involved consultant being the one released instead, or a short delay to the new contract's start date).
Step 3 - Do not unilaterally agree to the change without raising it with the client first. Given the client's Control Team Lead has explicitly and previously valued personnel consistency on this sensitive engagement, quietly reducing this key consultant's involvement without informing them would be a significant transparency and governance failure - echoing the syllabus principle that clients should be informed proactively of matters materially affecting delivery, rather than left to discover changes after the fact. Even if you ultimately judge the reduced arrangement could work technically, informing the client's Control Team Lead in advance, and giving them the opportunity to raise any concern, is professionally and contractually the correct approach.
Step 4 - Push back constructively with your own firm's leadership, using evidence, not just refusal. You should raise your assessment (Steps 1-2) directly and professionally with your Practice Director: explaining the specific, concrete risk to quality and safety on a live, sensitive, regulator-relevant engagement, and the consultant's own well-founded professional concern, rather than either simply refusing outright with no explanation, or simply complying because of internal hierarchy pressure - consistent with the syllabus principle that a Red Team Manager must actively and transparently manage tension between commercial pressure and maintaining professional/safety standards, rather than letting commercial pressure automatically prevail.
Step 5 - Propose alternatives that could satisfy both needs. Rather than a binary "yes" or "no," propose constructive alternatives to your Practice Director: for example, releasing a different, less critically-placed team member for the new contract instead; a short, defined delay (e.g., one to two weeks) before this consultant transitions, timed to a genuine, planned handover point in the TIBER-EU engagement's own workplan; or bringing in additional short-term support to properly backfill and hand over the consultant's specific attack-path knowledge before any reduction in their time takes effect, consistent with the succession
/continuity planning principle discussed elsewhere in the syllabus.
Step 6 - If a change genuinely must proceed, manage it properly rather than allowing an uncontrolled drift.
If, after this escalation, your firm's leadership still determines the consultant must move to the new contract at least part-time, you should ensure this happens through a properly managed, documented transition - informing the client's Control Team Lead transparently with your own honest risk assessment, agreeing a specific handover plan and, if necessary, adjusting the TIBER-EU engagement's own remaining timeline or approach to reflect the reduced resourcing honestly, rather than pretending nothing has changed.
Step 7 - Reflect this into future capacity planning. This episode should be captured as a lessons-learned point about the firm's broader capacity planning practice: committing key personnel fully to sensitive, lengthy, regulator-relevant engagements needs to be genuinely protected against exactly this kind of internal competing-priority pressure, ideally through better forward capacity planning before new contracts are sold in, rather than resolved reactively each time it arises.
Conclusion: The consultant's professional concern about harmful context-switching should be taken seriously and used as the basis for pushing back constructively (not simply complying) with your own firm's commercial leadership; the client's Control Team Lead must be informed transparently before any change is made, given their previously stated value on personnel consistency; and if a change ultimately must proceed, it should be managed through a properly planned, documented, and client-informed transition rather than an unmanaged, silent reduction in a key consultant's involvement.
---

弊社は製品に自信を持っており、面倒な製品を提供していません。


-Hirase

