
Certified Tester Security Tester
Domain 6Objective 3
Common Motivations and Sources of Computer System Attacks CT-SEC Practice Questions (Page 4)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
3concepts
Questions 16–20
- 16
A security analyst is investigating a breach at a financial institution. The attack involved a sophisticated phishing campaign that targeted high-level executives, and the malware used was previously unseen. The stolen data includes customer financial records, which have not appeared on any dark web marketplaces. The attack infrastructure is traced to a country known for state-sponsored cyber operations. Which source of attack is most likely, and what is the primary motivation?
Select an answer first - 17
A security analyst is reviewing a series of attacks. The first attack involved a ransomware infection that encrypted files and demanded payment in cryptocurrency. The second attack involved a data breach where sensitive government documents were leaked to the press. The third attack involved a DDoS attack on a corporation that was accused of environmental pollution. Which set of motivations best matches these attacks in order?
Select an answer first - 18
A security analyst discovers that a disgruntled employee used their valid credentials to access sensitive files after being fired. Which source of attack does this scenario describe?
Select an answer first - 19
A company's security breach occurs because an employee accidentally sent a confidential file to the wrong recipient. Which human factor directly caused this breach?
Select an answer first - 20
A user receives an email that appears to be from a colleague, asking them to review a document attached as a .docx file. The email address is the colleague's real address, but the attachment contains a macro that installs malware. The user opens the attachment because they recognize the sender. Which human factor is most directly exploited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.