
Certified Tester Security Tester
Domain 9Objective 6
Evaluating Security Testing Practices for Improvements CT-SEC Practice Questions (Page 5)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 21–23
- 21
A company's security team wants to implement a new security testing methodology. They have a limited budget and a small team. They need to choose between implementing a comprehensive SAST tool across their entire codebase or implementing a targeted DAST solution for their top 5 critical web applications. The team's goal is to reduce the number of high-severity vulnerabilities in production. Which approach is more likely to achieve this goal in the short term?
Select an answer first - 22
What is the main goal of identifying improvement opportunities in security testing practices?
Select an answer first - 23
A large e-commerce company has a mature security testing program. They perform SAST on every commit, DAST on every staging build, and a full penetration test before each major release. The program has a low false-positive rate and high code coverage. However, the security team is concerned that they are not effectively testing the security of their microservices architecture, which has grown to over 200 services. They want to evaluate the effectiveness of their current practices against this new architecture. What is the most significant gap in their current testing practices?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.