
Certified Tester Security Tester
Domain 1Objective 2
Asset Identification CT-SEC Practice Questions (Page 4)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
Questions 16–20
- 16
A security tester is conducting an assessment for a large enterprise. The asset inventory is comprehensive but lists the 'owner' of a critical financial reporting system as 'IT Operations'. However, the IT Operations team states they only manage the infrastructure (servers, OS) and do not own the application or its data. The actual business owner is the CFO's office. The tester discovers a critical vulnerability in the application. What is the MOST significant challenge this ownership ambiguity creates for the security test?
Select an answer first - 17
Why is the disposal stage of the asset lifecycle relevant to security testing?
Select an answer first - 18
Which of the following is an example of reputational impact in asset value assessment?
Select an answer first - 19
What is the primary purpose of the asset identification process in security testing?
Select an answer first - 20
Which of the following is a common criterion used to classify assets?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.