Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Acceptance Testing

Domain 4Objective 4

Objective: Security CT-ACT Practice Questions (Page 2)

Part of the Domain 4: Acceptance Testing for Non-Functional Requirements domain, which makes up ~28% of our current practice bank. ISTQB does not publish an official question count, but from its 60-minute exam (~25–40 total, ~7–11 in this domain), expect 2–3 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
5concepts

Questions 6–10

  1. 6application · medium

    An e-commerce company is planning acceptance testing for a new payment processing module. The team has identified several potential security issues: a SQL injection vulnerability in the search function (high impact, high likelihood), a cross-site scripting issue in the review section (medium impact, high likelihood), and a theoretical denial-of-service risk from a misconfigured load balancer (high impact, low likelihood). The team has limited time for testing. What should the acceptance test plan prioritize?

    Select an answer first
  2. 7expert · hard

    After completing security acceptance testing for a new government portal, the team has identified three findings: a high-severity issue where encrypted data can be decrypted with a known key (affects 1% of users), a medium-severity issue where user sessions do not expire (affects all users), and a low-severity issue where the password policy allows weak passwords. The system must be released next week for a regulatory deadline. The team can fix only one issue before release. Which finding should be fixed first?

    Select an answer first
  3. 8expert · hard

    After security acceptance testing of a new HR system, the team has identified the following findings: a critical issue where any authenticated user can view all employee salaries (affects all users), a medium issue where password reset tokens are not invalidated after use (affects a small number of users), and a low issue where the system logs contain plaintext passwords (affects all users). The release is scheduled for tomorrow, and the team can fix only one issue. Which finding should be fixed before release?

    Select an answer first
  4. 9foundation · medium

    Which of the following is an example of a residual risk that might be identified during security test result evaluation?

    Select an answer first
  5. 10application · medium

    A healthcare startup is developing a patient portal that will store protected health information. During acceptance test planning, the product owner states that the system must ensure that only authorized clinicians can view patient records, that records cannot be altered without an audit trail, and that the portal remains accessible during business hours. The team is now writing acceptance test scenarios. Which set of security requirements should the acceptance tests be designed to verify?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-ACT” is a trademark of its owner, used for identification only.