
Certified Tester Security Tester
Domain 5Objective 7
Data Obfuscation CT-SEC Practice Questions (Page 4)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
8concepts
Questions 16–20
- 16
What is the primary purpose of data obfuscation in a software system?
Select an answer first - 17
A security tester is assessing a data masking implementation that replaces customer names with random names. The tester notices that the masked data still preserves the original name length and the first letter. What type of information leakage does this reveal?
Select an answer first - 18
Which data obfuscation technique replaces sensitive values with non-sensitive substitutes that have no meaningful relationship to the original data?
Select an answer first - 19
A financial institution is implementing data obfuscation across its systems. The security team has identified that customer account numbers appear in multiple databases, log files, and API responses. They want to ensure that all occurrences of account numbers are obfuscated consistently. What should the security team do first to assess the coverage of obfuscation?
Select an answer first - 20
Which metric is most relevant when evaluating the performance impact of obfuscation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.