
Certified Tester Security Tester
Domain 9Objective 6
Evaluating Security Testing Practices for Improvements CT-SEC Practice Questions (Page 3)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 11–15
- 11
A company has a security testing process that includes a weekly vulnerability scan and a monthly manual review of the findings. The team notices that the same medium-severity vulnerabilities are being reported every week, but they are not being fixed. The team wants to evaluate the effectiveness of their security testing practice. What is the primary weakness in this practice?
Select an answer first - 12
What is the primary purpose of evaluating security testing practices against defined criteria?
Select an answer first - 13
A healthcare organization's security testing program consists of uncoordinated ad-hoc vulnerability scans performed by different teams. The organization wants to implement a structured methodology to improve its security testing practices. Which approach best aligns with a structured improvement methodology?
Select an answer first - 14
A company's security team has a testing program that includes a monthly vulnerability scan and a quarterly penetration test. They want to evaluate the effectiveness of their program. They have a list of all known vulnerabilities in their environment, but they are unsure if their testing is finding them all. What is the best way to evaluate the effectiveness of their testing program?
Select an answer first - 15
A company's security team has a testing program that is heavily focused on external-facing web applications. They have recently deployed a new internal application that handles employee PII. The team wants to improve their testing practice to cover this new asset. They have a limited budget and cannot afford a full penetration test for the internal application. What is the most effective improvement to address this gap?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.