
Certified Tester Security Tester
Domain 5Objective 2
Authentication and Authorization CT-SEC Practice Questions (Page 7)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
10concepts
Questions 31–33
- 31
Which security testing technique is used to verify that an application resists automated password guessing attacks?
Select an answer first - 32
Which statement best defines authorization in the context of security testing?
Select an answer first - 33
A tester changes a user ID in a request from '123' to '124' and finds that they can access another user's account data. Which type of authorization flaw does this demonstrate?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.