
Certified Tester Security Tester
Domain 9Objective 4
Applying Security Standards CT-SEC Practice Questions (Page 4)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 16–20
- 16
Which of the following is a security standard that provides a framework for managing information security risks and is commonly referenced in software testing to align with organizational security policies?
Select an answer first - 17
A security test team is working on a project for a client that must comply with both PCI DSS and the OWASP ASVS. The client has a limited budget and wants to minimize testing effort while still meeting both standards. The test lead is deciding how to structure the test plan. What is the most efficient approach?
Select an answer first - 18
When applying the OWASP Testing Guide to a web application security test, which of the following activities is directly aligned with the guide's recommendations?
Select an answer first - 19
A security tester is working on a project for a client that requires testing to be aligned with a framework that covers both management and technical controls. The client wants a single framework that can be used to assess the overall security posture. Which framework is most appropriate?
Select an answer first - 20
Which framework is specifically designed to guide the development of secure software by providing a set of security requirements and best practices for each phase of the software development lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.