
Certified Tester Security Tester
Domain 5Objective 2
Authentication and Authorization CT-SEC Practice Questions (Page 5)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
10concepts
Questions 21–25
- 21
A tester changes a request parameter from 'role=user' to 'role=admin' to see if the application grants higher privileges. Which security testing technique is this?
Select an answer first - 22
A security tester is reviewing a web application that uses role-based access control. The tester logs in as a standard user and manually changes the 'role' parameter in the URL from 'user' to 'admin'. The application then grants administrative functions. Which type of authorization flaw is being demonstrated?
Select an answer first - 23
A tester with a standard user account directly requests the URL '/admin/deleteUser' and successfully deletes a user. Which authorization weakness does this reveal?
Select an answer first - 24
A security tester is assessing an application that uses biometric authentication. The tester discovers that the application stores biometric data in an unencrypted database. Which of the following is the most significant security risk associated with this finding?
Select an answer first - 25
Which of the following is an example of a common authentication mechanism?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.