
Certified Tester Security Tester
Domain 4Objective 3
Component and Integration Testing CT-SEC Practice Questions (Page 3)
Part of the Security Testing Throughout the Software Lifecycle domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)
15questions here
3free pages
5concepts
Questions 11–15
- 11
During integration testing of a microservices-based application, the team wants to verify that the order service correctly passes authentication tokens to the payment service. Which security testing technique is most appropriate?
Select an answer first - 12
A development team is writing a new authentication module for a web application. During component testing, they want to verify that the module correctly rejects passwords that are too short, too long, or contain invalid characters. Which security testing approach is most appropriate for this stage?
Select an answer first - 13
During component-level security testing, which activity is most appropriate to perform?
Select an answer first - 14
During component integration testing, what is a key security testing technique?
Select an answer first - 15
When designing security test cases for a component, which focus area is most relevant?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.