You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The ISTQB® Certified Tester Security Tester (CT-SEC) certification validates your ability to plan, perform, and evaluate security tests from multiple perspectives—risk, requirements, vulnerability, and human factors. It is designed for testers with some security testing experience who want to deepen their expertise. Earning it demonstrates that you can align security testing with the software lifecycle, apply security mechanisms, and use the right tools and standards to protect your organization.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The ISTQB® Certified Tester Security Tester (CT-SEC) certification focuses on planning, performing, and evaluating security tests from multiple perspectives including risk, requirements, vulnerability, and human factors. It also covers security testing tools and standards, giving you a comprehensive framework to identify and mitigate security risks throughout the software development lifecycle.
By earning CT-SEC, you demonstrate the ability to analyze security policies and procedures, evaluate the effectiveness of security mechanisms, and adopt an attacker mentality to uncover vulnerabilities in a protected environment. You will also learn to select and apply appropriate security testing tools, understand industry standards, and contribute to building information security awareness within your organization.
The Security Tester certification is aimed at people who have some experience in security testing and wish to further develop their expertise in security testing. It is ideal for testers, security analysts, and quality assurance professionals who are responsible for ensuring the security of software systems. Candidates should be comfortable with fundamental testing concepts and have practical experience in security testing. The certification is designed to help you advance your career by validating your specialized skills in security testing.
Candidates should have some experience in security testing and a solid understanding of software testing fundamentals. ISTQB recommends at least three years of relevant academic, practical, or consulting experience. Experience in planning and executing security tests; Knowledge of security risks, vulnerabilities, and attack vectors; Familiarity with security testing tools and standards; Understanding of the software development lifecycle and testing processes
Every domain and objective ISTQB measures, with the weight they carry on the exam.
The official ISTQB exam outline · checked 30 July 2026 · See the source
Everything ISTQB publishes about sitting it, and nothing we inferred.
Must hold the Certified Tester Foundation Level (CTFL) certificate.
The path ISTQB lays out, how the credential is kept, and where to book.
Step-by-step path to Certified Tester Security Tester
ISTQB certifications do not require renewal except for Expert Level. The CT-SEC certification does not require renewal. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. ISTQB maintains this certification to validate current skills and industry relevance.
Register for the exam through ISTQB Member Boards, ISTQB’s authorized testing partner.
Schedule your examVisit the official ISTQB certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksCT-SEC focuses on planning, performing, and evaluating security tests from multiple perspectives, while CT-STE equips professionals with essential skills to address evolving security testing challenges such as asset protection, audits, and adapting to new threats. Both are Specialist-level certifications, but CT-STE is a distinct, newer certification.
Yes, you must hold the Certified Tester Foundation Level (CTFL) certificate to be eligible for the CT-SEC exam. This is a mandatory prerequisite.
Yes, self-study using the official syllabus and recommended reading material is an option. However, ISTQB highly recommends attending accredited training to ensure the materials are relevant and consistent with the syllabus.
The CT-SEC exam consists of 45 multiple-choice questions. You have 120 minutes to complete it, with an additional 25% time if you are taking the exam in a non-native language.
No, the CT-SEC exam is a multiple-choice exam. There are no hands-on or lab components.
The CT-SEC certification is relevant for security testers, security analysts, and quality assurance professionals who are responsible for planning, performing, and evaluating security tests.
Yes, holders of the CT-SEC certification may choose to proceed to other Core, Agile, or Specialist stream certifications.
Every domain, every objective, and every concept ISTQB measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official ISTQB exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
27 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 49 objectives, 278 concepts written under them, and free questions against every one. When ISTQB changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.