
Certified Tester Security Tester
Domain 9Objective 2
Applicability of Standards in Regulatory Versus Contractual Situations CT-SEC Practice Questions (Page 1)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 14 practice questions to prepare you well beyond it. (estimate)
14questions here
3free pages
6concepts
Questions 1–5
- 1
A healthcare organization in the United States is required to comply with HIPAA. They hire an external security testing firm to assess their systems. The testing firm's report will be used to demonstrate compliance to the Office for Civil Rights (OCR) during an audit. What is the most critical consideration for the security testing firm?
Select an answer first - 2
How do contractual standards affect the scope of security testing?
Select an answer first - 3
How do regulatory standards influence security testing activities?
Select an answer first - 4
A multinational corporation operates a data center in the EU and a subsidiary in a non-EU country. The EU data center processes personal data of EU citizens and is subject to GDPR. The non-EU subsidiary is not subject to GDPR but has a contract with the EU parent company that requires adherence to GDPR principles. A security test is planned for both locations. Which statement accurately describes the legal basis for the security testing requirements?
Select an answer first - 5
How does the regulatory nature of a standard influence the reporting of security testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.