
Certified Tester Security Tester
Domain 9Objective 4
Applying Security Standards CT-SEC Practice Questions (Page 2)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 6–10
- 6
A security tester is using the OWASP ASVS (Application Security Verification Standard) to guide the testing of a new web application. Which of the following actions best demonstrates the application of ASVS?
Select an answer first - 7
A financial services firm is developing a mobile banking app and must comply with PCI DSS. The security test team is planning the test phases. Which testing activity is most directly mandated by PCI DSS requirements?
Select an answer first - 8
A security test team is testing a mobile application that processes personal data. The organization must comply with GDPR. The team is designing test cases for data protection. Which test case is most directly aligned with GDPR requirements?
Select an answer first - 9
During the reporting phase of a security test, how does the use of a standard like OWASP ASVS affect the way test results are documented?
Select an answer first - 10
A security tester is evaluating a set of standards to use for a new project. The project involves a web application that will be publicly accessible and will handle user credentials. The tester wants a standard that provides specific, actionable requirements for verifying the security of the application. Which standard is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.