Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 8Objective 4

Evaluating a Tool Vendor's Capabilities CT-SEC Practice Questions (Page 1)

Part of the Security Testing Tools domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
10concepts

Questions 1–5

  1. 1foundation · easy

    Why is it important to review a vendor's product roadmap when selecting a security testing tool?

    Select an answer first
  2. 2expert · hard

    A security team is evaluating two DAST vendors for a 3-year engagement. Vendor A has a strong market reputation and a large customer base, but its product roadmap is conservative, with no planned support for the team's upcoming GraphQL API testing needs. Vendor B is newer, with fewer customers, but its roadmap includes GraphQL testing in the next release. The team's primary requirement is to test GraphQL APIs within the next 12 months. Which vendor should the team select?

    Select an answer first
  3. 3expert · hard

    A security team is evaluating a new RASP vendor. The vendor's support team is known for being responsive, but the contract's SLA only guarantees a 48-hour response time for critical issues. The team's security operations center operates 24/7 and expects a response within 4 hours for critical incidents. The vendor is the only one that meets all other technical requirements. What should the team do?

    Select an answer first
  4. 4foundation · easy

    What is the primary purpose of conducting a proof of concept (PoC) for a security testing tool?

    Select an answer first
  5. 5expert · hard

    A company is evaluating two SAST vendors. Vendor A charges a flat annual fee based on the number of lines of code (LOC). Vendor B charges per developer per month. The company has 200 developers and a codebase of 5 million LOC, which is expected to grow by 20% annually. The security team expects to add 50 developers in the next year. Which vendor's licensing model is likely to be more cost-effective over the next three years?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.