
Certified Tester Security Tester
Domain 5Objective 3
Encryption CT-SEC Practice Questions (Page 5)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
7concepts
Questions 21–25
- 21
Which of the following best describes a key difference between symmetric and asymmetric encryption?
Select an answer first - 22
Which of the following is a characteristic of the AES algorithm?
Select an answer first - 23
What is a side-channel attack in the context of encryption?
Select an answer first - 24
A tester is assessing a custom encryption library used by an application. The library implements AES-CBC with PKCS#7 padding. The tester sends a modified ciphertext to the application and observes that the application returns different error messages for 'invalid padding' versus 'invalid MAC'. Which vulnerability is the tester likely exploiting?
Select an answer first - 25
A healthcare organization must protect patient records stored in a database. The compliance requirement states that data must be encrypted at rest. The organization also needs to be able to search for specific patient records without decrypting the entire database. Which approach should the tester recommend?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.