
Certified Tester Security Tester
Domain 5Objective 7
Data Obfuscation CT-SEC Practice Questions (Page 1)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
8concepts
Questions 1–5
- 1
In which scenario is data obfuscation most commonly applied?
Select an answer first - 2
Which of the following is a common reason why obfuscation coverage might be incomplete?
Select an answer first - 3
A marketing company is collecting customer data for targeted advertising. They want to share the data with a third-party analytics firm, but they are concerned about privacy regulations. They decide to use data obfuscation to protect the data. Which statement best describes the purpose of data obfuscation in this context?
Select an answer first - 4
A security team is assessing the coverage of data obfuscation in a large enterprise system. They have identified that customer credit card numbers are stored in a database, appear in application logs, and are included in API responses. They want to ensure that all these instances are obfuscated. What is the most effective way to assess coverage?
Select an answer first - 5
A security tester is evaluating a data masking implementation that replaces email addresses with random strings. The tester notices that the masked emails still contain the same domain name as the original (e.g., @company.com). What is the potential risk of this leakage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.