Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB

Certified Tester Security Tester

CT-SEC

The ISTQB® Certified Tester Security Tester (CT-SEC) certification validates your ability to plan, perform, and evaluate security tests from multiple perspectives—risk, requirements, vulnerability, and human factors. It is designed for testers with some security testing experience who want to deepen their expertise. Earning it demonstrates that you can align security testing with the software lifecycle, apply security mechanisms, and use the right tools and standards to protect your organization.

1239 practice questions · Updated 2026-07-30

9Domains
49Objectives
278Concepts
1239Questions

CT-SEC Curriculum

Every domain, objective, and concept the CT-SEC exam measures.

  1. Risk Assessment Fundamentals
  2. Risk Identification
  3. Risk Analysis
  4. Risk Evaluation
  5. Risk Treatment Options
  6. Integrating Risk Assessment into Test Planning
  7. Risk-Based Test Design
  8. Risk Communication and Reporting

Asset Identification

9 concepts · 31 questions
  1. Definition of Assets
  2. Asset Identification Process
  3. Asset Inventory
  4. Asset Classification
  5. Asset Ownership
  6. Asset Value Assessment
  7. Asset Dependencies
  8. Asset Lifecycle
  9. Asset Documentation

Analysis of Risk Assessment Techniques

6 concepts · 30 questions
  1. Risk Assessment Fundamentals
  2. Risk Identification Techniques
  3. Risk Analysis Approaches
  4. Risk Evaluation and Prioritization
  5. Risk Treatment Options
  6. Risk Assessment Outputs
  1. Define Security Policies
  2. Define Security Procedures
  3. Distinguish Policies from Procedures
  4. Identify Policy Types
  5. Understand Policy Compliance
  6. Apply Policies in Testing
  1. Security Policy Analysis
  2. Security Procedures Evaluation
  3. Gap Identification
  4. Regulatory Compliance Review
  5. Risk Assessment Integration
  6. Recommendation Formulation

Purpose of a Security Audit

10 concepts · 35 questions
  1. Definition of Security Audit
  2. Objectives of Security Audit
  3. Scope of Security Audit
  4. Types of Security Audits
  5. Security Audit Process
  6. Roles and Responsibilities
  7. Audit Criteria and Standards
  8. Deliverables of Security Audit
  9. Difference Between Audit and Assessment
  10. Importance of Security Audit
  1. Risk Identification
  2. Risk Assessment
  3. Risk Mitigation
  4. Risk Communication

People, Process and Technology

4 concepts · 27 questions
  1. People in Security Testing
  2. Process in Security Testing
  3. Technology in Security Testing
  4. Interplay of People, Process, and Technology

Foundations of Security Testing

4 concepts · 21 questions
  1. Introduction to Security Testing
  2. Purpose of Security Testing
  3. Organizational Context of Security Testing
  4. Information Assurance vs. Security Testing
  1. Aligning Security Testing Goals
  2. Defining Security Test Objectives
  3. Determining Scope of Security Testing
  4. Determining Coverage of Security Testing
  1. Security Test Approaches
  2. Analysis of Security Test Approaches
  3. Failures in Security Test Approaches
  4. Stakeholder Identification

Improving Security Testing Practices

1 concepts · 19 questions
  1. Improving Security Testing Practices

Security Testing Process Overview

2 concepts · 22 questions
  1. ISTQB Security Testing Process
  2. Aligning Security Testing to Lifecycle Models

Security Test Planning

4 concepts · 22 questions
  1. Security Test Planning Objectives
  2. Key Security Test Plan Elements
  3. Importance of Planning in Security Testing
  4. Importance of Approvals in Security Testing

Security Test Design

3 concepts · 23 questions
  1. Security Test Design Fundamentals
  2. Security Test Design Techniques
  3. Security Test Design Based on Policies and Procedures

Security Test Execution and Evaluation

6 concepts · 22 questions
  1. Effective Security Test Environment Characteristics
  2. Security Test Environment Setup
  3. Security Test Execution Monitoring
  4. Security Test Results Analysis
  5. Security Test Evaluation Criteria
  6. Security Test Reporting and Documentation

Security Test Maintenance

6 concepts · 25 questions
  1. Security Test Maintenance Overview
  2. Identifying Maintenance Triggers
  3. Updating Security Test Cases
  4. Retesting and Regression Testing
  5. Managing Test Assets
  6. Continuous Improvement of Security Tests

Lifecycle Overview

4 concepts · 26 questions
  1. Lifecycle View of Security Testing
  2. Security Activities in Each Lifecycle Phase
  3. Shift-Left and Continuous Security Testing
  4. Roles and Responsibilities in Lifecycle Security

Requirements and Design

9 concepts · 37 questions
  1. Role of Security Testing in Requirements
  2. Security Requirements Elicitation
  3. Threat Modeling in Requirements
  4. Security Risk Assessment in Requirements
  5. Role of Security Testing in Design
  6. Security Design Review
  7. Security Architecture Analysis
  8. Design-Level Threat Modeling
  9. Security Test Planning in Design

Component and Integration Testing

5 concepts · 15 questions
  1. Security Testing During Component Testing
  2. Security Test Design at the Component Level
  3. Analysis of Security Tests at the Component Level
  4. Security Testing During Component Integration Testing
  5. Security Test Design at the Component Integration Level

System, Acceptance, and Maintenance

3 concepts · 23 questions
  1. Security Testing in System Testing
  2. Security Testing in Acceptance Testing
  3. Security Testing in Maintenance

System Hardening

4 concepts · 24 questions
  1. System Hardening Fundamentals
  2. Hardening Mechanisms and Techniques
  3. Testing Hardening Effectiveness
  4. Assessing Hardening Gaps

Authentication and Authorization

10 concepts · 33 questions
  1. Definition of Authentication
  2. Definition of Authorization
  3. Relationship Between Authentication and Authorization
  4. Authentication Mechanisms
  5. Authorization Models
  6. Testing Authentication Effectiveness
  7. Testing Authorization Effectiveness
  8. Common Authentication and Authorization Vulnerabilities
  9. Security Testing Techniques for Authentication
  10. Security Testing Techniques for Authorization

Encryption

7 concepts · 26 questions
  1. Encryption Fundamentals
  2. Symmetric vs. Asymmetric Encryption
  3. Common Encryption Algorithms
  4. Encryption Key Management
  5. Encryption Implementation Testing
  6. Common Encryption Vulnerabilities
  7. Encryption Compliance and Standards

Firewalls

8 concepts · 20 questions
  1. Firewall Fundamentals
  2. Firewall Architecture and Placement
  3. Firewall Rule Analysis
  4. Firewall Policy Review
  5. Firewall Configuration Testing
  6. Firewall Bypass Techniques
  7. Firewall Logging and Monitoring
  8. Firewall Performance and Availability Testing

Intrusion Detection

8 concepts · 22 questions
  1. Intrusion Detection Fundamentals
  2. Types of Intrusion Detection Systems
  3. Common Intrusion Detection Tools
  4. IDS Deployment and Configuration
  5. Testing IDS Effectiveness
  6. Evaluating IDS Detection Accuracy
  7. Bypassing and Evasion Techniques
  8. IDS Alert Analysis and Reporting

Malware Scanning

6 concepts · 32 questions
  1. Malware Scanning Tools Overview
  2. Tool Capabilities and Limitations
  3. Deployment and Configuration
  4. Effectiveness Testing Methodology
  5. Interpreting Scan Results
  6. Reporting and Recommendations

Data Obfuscation

8 concepts · 21 questions
  1. Definition and Purpose of Data Obfuscation
  2. Common Data Obfuscation Techniques
  3. Obfuscation in Different Contexts
  4. Testing Obfuscation Effectiveness
  5. Assessing Obfuscation Coverage
  6. Verifying Obfuscation Consistency
  7. Testing for Reversibility and Leakage
  8. Evaluating Performance Impact

Security Training

9 concepts · 35 questions
  1. Importance of Security Training
  2. Security Training Objectives
  3. Security Training Content Areas
  4. Security Training Delivery Methods
  5. Security Training Target Audiences
  6. Metrics for Training Effectiveness
  7. Testing Methods for Training Effectiveness
  8. Analyzing Training Test Results
  9. Continuous Improvement of Security Training

  1. Human factors in security
  2. Social engineering
  3. Phishing and pretexting
  4. Password hygiene
  5. Insider threats
  6. Security awareness training
  7. Behavioral risk mitigation

Understanding the Attacker Mentality

6 concepts · 28 questions
  1. Attacker Mindset
  2. Attack Motivations
  3. Attack Planning
  4. Exploitation Techniques
  5. Human Factors in Attacks
  6. Defensive Mindset
  1. Motivations for attacks
  2. Sources of attacks
  3. Human factors in attack vectors
  1. Attack Scenarios
  2. Motivations of Attackers
  3. Human Factors in Attacks
  4. Impact of Human Factors

Social Engineering

5 concepts · 25 questions
  1. Social Engineering Fundamentals
  2. Attack Vectors
  3. Human Vulnerabilities
  4. Mitigation Strategies
  5. Testing Techniques

The Importance Of Security Awareness

5 concepts · 23 questions
  1. Definition of Security Awareness
  2. Importance of Human Factors
  3. Common Human-Related Threats
  4. Benefits of Security Awareness
  5. Security Awareness in Testing

Increasing Security Awareness

4 concepts · 25 questions
  1. Define security awareness
  2. Identify human factors in security
  3. Describe awareness training methods
  4. Apply awareness in testing

Security Test Evaluation

8 concepts · 30 questions
  1. Security Test Evaluation Fundamentals
  2. Evaluation of Security Test Results
  3. Risk-Based Evaluation
  4. Prioritization of Findings
  5. False Positive and False Negative Analysis
  6. Root Cause Analysis
  7. Evaluation of Security Controls
  8. Reporting Evaluation Outcomes
  1. Confidentiality principles
  2. Handling sensitive test data
  3. Access control for test results
  4. Reporting and communication
  5. Legal and contractual obligations
  1. Purpose of interim security test status reports
  2. Components of an interim security test status report
  3. Interpreting test progress metrics
  4. Evaluating security findings and their impact
  5. Communicating interim status to stakeholders
  6. Identifying deviations from the test plan
  7. Updating risk assessment based on interim results

  1. Static Analysis Tools
  2. Dynamic Analysis Tools
  3. Penetration Testing Tools
  4. Vulnerability Scanning Tools
  5. Fuzzing Tools
  6. Web Application Security Tools
  7. Network Security Tools
  8. Mobile Application Security Tools
  9. Database Security Tools
  10. Code Review Tools
  11. Threat Modeling Tools
  12. Security Information and Event Management (SIEM) Tools
  13. Forensic Tools
  14. Compliance and Audit Tools
  1. Security Testing Needs Analysis
  2. Documentation of Security Testing Needs

Issues with Open Source Tools

6 concepts · 25 questions
  1. Identify common limitations of open source security testing tools
  2. Assess maintenance and community activity
  3. Evaluate integration and compatibility challenges
  4. Analyze scalability and performance constraints
  5. Recognize licensing and legal risks
  6. Mitigate risks through tool selection and supplementary measures

Evaluating a Tool Vendor's Capabilities

10 concepts · 32 questions
  1. Vendor capability assessment criteria
  2. Tool functionality evaluation
  3. Vendor support and maintenance
  4. Vendor reputation and market presence
  5. Cost and licensing model
  6. Integration and compatibility
  7. Scalability and performance
  8. Vendor roadmap and innovation
  9. Trial and proof of concept
  10. Vendor contract and SLA review

  1. Identify benefits of security testing standards
  2. Recognize standards' role in compliance
  3. Understand standards' impact on quality and efficiency
  4. Apply standards to improve communication
  1. Regulatory standards
  2. Contractual standards
  3. Differences between regulatory and contractual standards
  4. Application of standards in regulatory contexts
  5. Application of standards in contractual contexts
  6. Impact on security testing activities

Selection of Security Standards

3 concepts · 19 questions
  1. Purpose of security standards
  2. Common security standards
  3. Selecting appropriate standards

Applying Security Standards

3 concepts · 23 questions
  1. Identify Security Standards
  2. Apply Security Standards
  3. Understand Standards Impact
  1. Evaluate security testing practices
  2. Identify improvement opportunities
  3. Apply improvement methodologies
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CT-SEC, so none is invented.