
Certified Tester Security Tester
Domain 6Objective 3
Common Motivations and Sources of Computer System Attacks CT-SEC Practice Questions (Page 1)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
3concepts
Questions 1–5
- 1
A security team is investigating a data breach where an employee's credentials were used to access a confidential project repository. The employee had recently received a phone call from someone claiming to be a new IT manager, asking for their password to 'update security settings.' The employee provided the password. The attack is traced to a known cybercrime group. Which combination of human factor and source is most accurate?
Select an answer first - 2
An employee receives a phone call from someone claiming to be from the IT help desk, asking the employee to 'verify' their password due to a 'security audit.' The caller knows the employee's name and department. The employee provides the password. Which human factor is most directly exploited?
Select an answer first - 3
A security analyst discovers that a competitor has been accessing the company's pricing information through a vulnerability in a public-facing web application. The competitor's IP addresses are traced to a known corporate espionage operation. What is the primary motivation for this attack?
Select an answer first - 4
A security team discovers that a disgruntled employee, who was recently terminated, had used their still-active credentials to access the company's customer database and exfiltrate records. The employee had been a system administrator with elevated privileges. Which source of attack does this scenario best illustrate?
Select an answer first - 5
A security analyst is investigating a breach where an employee's credentials were used to access a customer database. The employee had recently received an email that appeared to be from the company's HR department, asking them to 'update their benefits information' by clicking a link. The link led to a fake login page that captured the credentials. The attack is traced to a known phishing group. Which human factor is most directly exploited, and what is the primary motivation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.