
Certified Tester Security Tester
Domain 9Objective 4
Applying Security Standards CT-SEC Practice Questions (Page 5)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 21–23
- 21
A security test team is preparing to test a web application that handles credit card transactions. The organization must comply with PCI DSS. The team is writing the test report. What information must be included in the report to demonstrate compliance?
Select an answer first - 22
A security tester is reviewing the test strategy for a new web application. The organization wants to ensure the testing aligns with industry best practices for web application security. Which standard is specifically designed as a testing guide for web application security?
Select an answer first - 23
A government contractor must align its software testing with NIST SP 800-53. The test manager is updating the test plan to meet the standard's requirements. What is the most appropriate action to ensure the test plan reflects NIST SP 800-53?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.