Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 6Objective 3

Common Motivations and Sources of Computer System Attacks CT-SEC Practice Questions (Page 2)

Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
3concepts

Questions 6–10

  1. 6application · medium

    A company's security team runs a phishing simulation and finds that 20% of employees clicked on a link in a fake email that promised a 'free coffee voucher.' The email was sent from an external address. Which human factor is most likely being exploited?

    Select an answer first
  2. 7application · medium

    A security analyst at a mid-sized bank notices a series of targeted phishing emails sent to employees in the wire-transfer department. The emails contain personalized information about recent transactions and urge employees to click a link to 'verify' a suspicious transfer. The attacker's infrastructure is traced to a known cybercrime group that historically demands ransom payments. Which combination of motivation and source best characterizes this attack?

    Select an answer first
  3. 8application · medium

    A hospital's IT department receives a call from a person claiming to be a vendor technician who needs the password to a critical medical device for 'urgent maintenance.' The caller is insistent and mentions the device's model number, which is publicly available in a brochure. A nurse provides the password. What human factor most directly enabled this attack?

    Select an answer first
  4. 9foundation · easy

    An attacker sends a convincing email to an employee, posing as the CEO and requesting an urgent wire transfer. Which human factor is primarily being exploited?

    Select an answer first
  5. 10foundation · easy

    Which source of attack is most likely to have the resources and long-term persistence to conduct a sophisticated campaign against a country's critical infrastructure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.