
Certified Tester Security Tester
Domain 1Objective 5
Analysis of Security Policies and Procedures CT-SEC Practice Questions (Page 5)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
Questions 21–25
- 21
Which activity is most likely to reveal a gap between a security procedure and its actual implementation?
Select an answer first - 22
What is the purpose of formulating recommendations after analyzing security policies and procedures?
Select an answer first - 23
A recent risk assessment identified that the company's remote access solution uses an outdated VPN protocol with known vulnerabilities. The security policy, however, only states that 'remote access must be provided to employees.' The tester is asked to analyze the policy in light of the risk assessment. What is the most appropriate action?
Select an answer first - 24
A security tester is evaluating the incident response procedure. The policy states that 'security incidents must be reported to the CISO within one hour of detection.' The procedure, however, instructs help desk staff to first verify the incident and then escalate, which typically takes two to three hours. What is the most appropriate finding?
Select an answer first - 25
A risk assessment found that the company's third-party vendors have access to sensitive data without regular security reviews. The security policy states that 'third-party access must be managed.' The tester is asked to analyze the policy in light of the risk assessment. What is the most appropriate recommendation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.