Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 1Objective 5

Analysis of Security Policies and Procedures CT-SEC Practice Questions (Page 1)

Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts

Questions 1–5

  1. 1application · medium

    A security tester is evaluating the access review procedure of a financial institution. The procedure requires that access rights be reviewed every 6 months, but the regulator mandates quarterly reviews. The policy does not specify a frequency. What is the most appropriate recommendation?

    Select an answer first
  2. 2foundation · easy

    What is a gap in the context of security policy and procedure analysis?

    Select an answer first
  3. 3application · medium

    A security tester is reviewing a company's data retention policy. The company processes credit card payments and stores customer data in a database. The policy states that 'all customer data is retained for 10 years for business purposes.' The tester notices that the company also stores cardholder data beyond the retention period required by the Payment Card Industry Data Security Standard (PCI DSS). What should the tester recommend?

    Select an answer first
  4. 4foundation · easy

    What is the main objective of a security policy analysis?

    Select an answer first
  5. 5foundation · easy

    Which of the following is an example of a regulatory requirement that might be reviewed in a security policy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.