Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 9Objective 6

Evaluating Security Testing Practices for Improvements CT-SEC Practice Questions (Page 2)

Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
3concepts

Questions 6–10

  1. 6application · medium

    A financial services company conducts penetration tests twice a year against its public web application. After each test, the security team fixes the reported vulnerabilities and closes the findings. However, the same classes of vulnerabilities (e.g., SQL injection, XSS) reappear in new features between tests. The team wants to improve the effectiveness of its security testing practice. Which improvement should the team prioritize?

    Select an answer first
  2. 7expert · hard

    A company has a security testing program that includes SAST, DAST, and penetration testing. The team is seeing a high number of false positives from their SAST tool, which is consuming significant time to triage. This is leading to 'alert fatigue' and the team is starting to ignore the tool's output. The team wants to improve the effectiveness of their testing practice. What is the most effective improvement to address this issue?

    Select an answer first
  3. 8application · medium

    A company's security team wants to implement a structured methodology to improve its security testing practices. They have a mature testing program but want to ensure it aligns with industry best practices. Which of the following is the most appropriate first step in applying a structured improvement methodology?

    Select an answer first
  4. 9application · medium

    A company's security team performs a penetration test once a year. The test is comprehensive and finds many vulnerabilities. However, the team notices that many of the vulnerabilities found in the test are in code that was written after the last test. The team wants to evaluate the effectiveness of their security testing practice. What is the primary weakness in this practice?

    Select an answer first
  5. 10foundation · easy

    What is the purpose of applying a structured improvement methodology to security testing practices?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.