CREST CCRTM-SC Exam Overview:
| Certification Vendor: | CREST |
|---|---|
| Exam Name: | CREST Certified Red Team Manager - Scenario |
| Exam Number: | CCRTM-SC |
| Exam Price: | £800 + VAT |
| Related Certifications: | CREST Certified Red Team Manager (CCRTM) |
| Exam Format: | Written Scenario, Scenario Question |
| Real Exam Qty: | 1 scenario question |
| Passing Score: | At least 84 marks out of 120 (70%) for the Scenario component |
| Available Languages: | English |
| Certificate Validity Period: | 3 years from the date the exam is sat |
| Exam Duration: | 180 minutes |
| Sample Questions: | CREST CCRTM-SC Sample Questions |
| Exam Way: | In-person computer-based examination at selected Pearson VUE test centres worldwide. The Scenario component is a closed-book written examination. Candidates receive an additional 15 minutes of reading time before the 3-hour Scenario exam. |
| Pre Condition: | No separate prerequisite exam is stated by CREST for the CCRTM examination; the CCRTM certification requires passing both the Multiple Choice & Long Form exam and the Scenario exam. |
| Official Syllabus URL: | https://www.crest-approved.org/ccrtm-faqs/ |
CREST CCRTM-SC Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Legal, Ethical and Moral Aspects of Attack Management | - Additional relevant legislation or contractual information - Ethical testing considerations - Data handling legislation - Privacy legislation - Inadvertent and Collateral targeting - Computer crime/cyber abuse and misuse legislation |
| Topic 2: Risk Management, Reporting and Communication | - Internationally Recognised Standards and Frameworks - Articulating Risk - Risk Management Lexicon - Engagement Risk Management |
| Topic 3: Key Concepts | - Red Team Frameworks - Terminology - Red team, Purple team testing, penetration testing - Detection and Response Assessment - Attack Path Mapping and Attack Path Simulation |
| Topic 4: Threat Intelligence | - Sources of Threat Intelligence - Considerations of Threat Models - Benefits of Active vs Passive Methodologies - Legalities / Ethics considerations of Threat Intelligence sources |
| Topic 5: Planning & Scoping | - Stakeholders for engagements - Requirements Analysis (scoping) |
| Topic 6: Project Management, Governance & Oversight | - Roles & responsibilities of the control group - Stakeholder Management & Engagement Integrity - Incident Management Response - Stages of a red team engagement - Communications plans |
| Topic 7: Attack Methodology, Key Stages & Common Frameworks | - Persistence Techniques and Risks - Physical access control bypasses and risks - Lateral Movement Techniques and Risks - Attack Methodology Frameworks - Privilege Escalation Techniques and Risks - Hybrid Environment Testing and Risks - Initial Access Techniques and Risks - Cloud Environment Testing and Risks |
| Topic 8: Rules of Engagement, Contingencies and Scenario Simulation | - Test plans - Types of scenarios - Rules of Engagements - Contingencies / Client Facilitation |
| Topic 9: Dropper/Implant Design, Safety and Secure Coding | - Secure Data Handling - Infrastructure Controls - Implant Controls - Implant Core capabilities and risks - Encryption vs Encoding - Persistent vs Semi-Persistent implant design and risks - Implant Droppers capabilities and risks |
CREST Certified Red Team Manager - Scenario Sample Questions:
Question 1
Background: You are the Red Team Manager on a CBEST-style engagement for Rowanmere Building Society. The Control Group consists of the CISO (chair), the Head of Operational Resilience, and the General Counsel. In week 3 of an 8-week Red Team testing phase, you receive an unusual, unscheduled email from the Head of IT Operations (not a Control Group member) stating: "I heard through a colleague that there's some kind of security exercise happening - is this you? If so, please stop targeting the payments infrastructure team specifically, they're stretched thin this month with a system migration." The email is polite but clearly indicates the Blue Team, or at least part of it, may have become aware of the exercise.
You also separately learn, through your own team's monitoring of the engagement's dedicated inbox, that the CISO forwarded a summary of "upcoming testing activity, including likely timing" to the Head of IT Operations two weeks earlier "so he wouldn't panic if he noticed anything odd," without informing the rest of the Control Group of this decision.
Question: Assess the significance of these two developments for the integrity of the engagement, and set out the steps you should take as Red Team Manager, including how you would engage the Control Group.
Question 2
Background: You are the Red Team Manager for a 12-week TIBER-EU-aligned engagement. In week 7, your firm wins a large, unrelated new contract that your firm's leadership is keen to staff quickly, and you are asked by your own Practice Director to release your firm's second-most-senior consultant on the current engagement
- who has been leading the more technically complex of two parallel attack paths - to begin work on the new contract "part-time, starting Monday, just two days a week for now," while remaining nominally on the TIBER-EU engagement the other three days.
The consultant in question tells you privately that they do not believe they can properly context-switch between a slow-paced, patient, intelligence-led campaign requiring sustained situational awareness of a live target environment, and a fast-moving new client kickoff, without a real risk of errors or missed detail on one or both engagements. Separately, the client's Control Team Lead has no visibility yet of this proposed change and has previously stressed how much they value consistency of personnel on such a sensitive, lengthy engagement.
Question: As Red Team Manager, how would you handle this internal resourcing request from your own firm's leadership, balancing your firm's commercial interests against your professional obligations on the current TIBER-EU engagement? Explain your reasoning and the steps you would take.
Solutions:
| Question 1 Answer: Only visible for members | Question 2 Answer: Only visible for members |
We're so confident of our products that we provide no hassle product exchange.


By Jeff

