
Certified Tester Security Tester
Domain 5Objective 2
Authentication and Authorization CT-SEC Practice Questions (Page 6)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
10concepts
Questions 26–30
- 26
A tester finds that the application accepts a session ID provided by the user in a URL parameter and does not generate a new session ID after login. Which vulnerability is this?
Select an answer first - 27
A security tester is explaining to a developer why a user who successfully logs in cannot access certain pages. The tester says, 'The user has been authenticated, but the application is now determining what the user is allowed to do.' Which security concept is the tester describing?
Select an answer first - 28
A security tester is evaluating an application that uses RBAC. The tester discovers that a user with the 'employee' role can access a function that should only be available to 'manager' role users. The tester confirms that the application checks the user's role on the client side and hides the function from the UI, but does not enforce the check on the server. Which of the following is the most appropriate recommendation?
Select an answer first - 29
In a security testing context, what is the primary purpose of authentication?
Select an answer first - 30
Which security testing technique involves directly requesting URLs or resources that are not linked in the application to see if they are accessible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.