
Certified Tester Security Tester
Domain 6Objective 3
Common Motivations and Sources of Computer System Attacks CT-SEC Practice Questions (Page 3)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
3concepts
Questions 11–15
- 11
Which motivation is most commonly associated with an attacker who defaces a government website to protest a political decision?
Select an answer first - 12
An employee receives an email that appears to be from the CEO, asking for the employee's login credentials to 'fix a payroll issue.' The email address is slightly different from the CEO's real address. The employee provides the credentials. Which human factor is most directly exploited in this attack?
Select an answer first - 13
A security team notices a pattern of attacks where a group of individuals, not affiliated with any state or criminal organization, is exploiting vulnerabilities in IoT devices to create a botnet. The botnet is used to launch DDoS attacks against companies that the group believes are harming the environment. What is the most likely source and motivation?
Select an answer first - 14
A company's security team discovers that an employee's credentials were used to access a sensitive database at 3:00 AM. The employee claims they were asleep and did not authorize the access. Further investigation reveals that the employee had recently clicked on a link in a phishing email that installed a keylogger. Which human factor is most directly responsible for the breach?
Select an answer first - 15
A security team is analyzing a series of attacks on a utility company. The first attack was a ransomware infection that disrupted operations. The second attack was a data breach where customer information was leaked to a news outlet. The third attack was a DDoS attack that targeted the company's public website. The attackers are believed to be a group that has previously claimed responsibility for attacks on other utilities. Which set of motivations best matches these attacks in order?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.