
Certified Tester Security Tester
Domain 1Objective 2
Asset Identification CT-SEC Practice Questions (Page 2)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
Questions 6–10
- 6
Why are asset dependencies important in security testing?
Select an answer first - 7
Which of the following is a typical component of an asset inventory entry?
Select an answer first - 8
A security tester is helping a manufacturing company classify its assets for a risk-based security test. The company has a production control system (PCS) that directly manages the assembly line, a sales CRM with customer contact data, and a public marketing website. The PCS is air-gapped from the corporate network. According to standard asset classification principles, which asset should be classified with the HIGHEST criticality?
Select an answer first - 9
A security tester is planning a test for a company that uses a legacy single sign-on (SSO) system. The SSO system is a dependency for the company's email, CRM, and file storage services. The SSO system is at the end of its lifecycle and is no longer patched. The tester has a limited budget and must choose between testing the SSO system or testing the email system. Which choice is more justified?
Select an answer first - 10
Which of the following is an example of an intangible asset in the context of security testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.