Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 5Objective 2

Authentication and Authorization CT-SEC Practice Questions (Page 1)

Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
10concepts

Questions 1–5

  1. 1application · medium

    A security tester is assessing an application that allows users to view their own invoices by clicking a link like /invoice?id=12345. The tester changes the id to another user's invoice number and successfully views it. Which testing technique did the tester use, and what vulnerability was confirmed?

    Select an answer first
  2. 2foundation · easy

    In a security testing scenario, what does authorization determine?

    Select an answer first
  3. 3expert · hard

    A security tester is analyzing a web application's session management. The tester logs in, receives a session ID, and then logs out. The tester then logs in again and receives the same session ID. The tester suspects a session fixation vulnerability. Which of the following is the most effective mitigation?

    Select an answer first
  4. 4foundation · easy

    Why must authentication occur before authorization in a secure system?

    Select an answer first
  5. 5foundation · easy

    Which statement best defines authentication in the context of security testing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.