
Certified Tester Security Tester
Domain 9Objective 6
Evaluating Security Testing Practices for Improvements CT-SEC Practice Questions (Page 1)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 1–5
- 1
A software company's security team performs a manual code review before each release. The reviews are thorough but take an average of 10 days, causing release delays. The team has a backlog of 50 identified issues, but 80% are low-severity style or linting problems. The team wants to improve the efficiency of its security testing practice without sacrificing security. What should the team do?
Select an answer first - 2
A company wants to implement a structured methodology to improve its security testing practices. The team is currently using a checklist of common vulnerabilities. They want to move to a more comprehensive and risk-based approach. Which methodology is most appropriate for this goal?
Select an answer first - 3
A company's security team has a mature testing program with SAST, DAST, and penetration testing. They have a low false-positive rate and high coverage. However, they are seeing an increase in security incidents related to business logic flaws (e.g., privilege escalation, broken access control) that are not being caught by their automated tools. The team wants to improve their testing practice to address this gap. What is the most effective improvement?
Select an answer first - 4
Which activity is most directly associated with identifying improvement opportunities in security testing?
Select an answer first - 5
A company's security team conducts regular penetration tests and vulnerability scans. They have a dashboard that tracks the number of open vulnerabilities by severity. The team wants to evaluate the effectiveness of their security testing practice. Which of the following metrics would provide the most insight into the effectiveness of the testing process itself?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.