
Certified Tester Security Tester
Domain 9Objective 2
Applicability of Standards in Regulatory Versus Contractual Situations CT-SEC Practice Questions (Page 2)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 14 practice questions to prepare you well beyond it. (estimate)
14questions here
3free pages
6concepts
Questions 6–10
- 6
In which context is a regulatory standard most likely to be mandatory?
Select an answer first - 7
A software vendor is negotiating a security assessment with a large enterprise client. The client insists that the assessment follow the PCI DSS requirements because the client processes credit card transactions. The vendor's standard methodology is based on the ISO/IEC 27001 framework. What is the most appropriate action for the vendor to take?
Select an answer first - 8
What role do acceptance criteria play in contractual security testing?
Select an answer first - 9
What is a key difference between regulatory and contractual standards?
Select an answer first - 10
What is a typical audit implication of a regulatory standard?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.