
Certified Tester Security Tester
Domain 1Objective 3
Analysis of Risk Assessment Techniques CT-SEC Practice Questions (Page 6)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
Questions 26–30
- 26
Which of the following is an example of a threat in a risk assessment?
Select an answer first - 27
After completing a risk assessment, a security tester produces a document that lists identified risks, their likelihood and impact ratings, and proposed treatment actions. What is this document called?
Select an answer first - 28
A security tester is evaluating risks for a financial application. The following risks have been identified. Which risks should be considered high priority based on a typical risk matrix? Select all that apply.
Select an answer first - 29
A security tester is comparing quantitative and qualitative risk analysis for a client. The client has a large amount of historical data on security incidents and wants to calculate the annualized loss expectancy (ALE) for each risk. However, the client also needs to communicate risks to non-technical stakeholders who prefer simple ratings. Which approach should the tester recommend?
Select an answer first - 30
A financial services company has identified a risk that a third-party payment processor may suffer a data breach, exposing customer payment data. The company decides to purchase cyber insurance to cover potential losses from such a breach. Which risk treatment strategy is the company applying?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.