
Certified Tester Security Tester
Domain 5Objective 4
Firewalls CT-SEC Practice Questions (Page 1)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
8concepts
Questions 1–5
- 1
Which firewall architecture involves a single, highly exposed host that is the primary point of contact for external connections?
Select an answer first - 2
What is the primary goal of high availability (HA) testing for a firewall?
Select an answer first - 3
When reviewing a firewall policy, which practice is considered a security best practice?
Select an answer first - 4
A security tester is analyzing a firewall rule set that contains the following rules in order: 1) allow tcp from any to web-server port 80; 2) allow tcp from any to web-server port 443; 3) deny tcp from any to any port 22; 4) allow tcp from any to any. The tester discovers that SSH traffic to the web server is being allowed, which is a violation of policy. Why is SSH being allowed?
Select an answer first - 5
A security analyst is reviewing firewall logs and notices that the log volume is very low, with only a few entries per day, despite the network having high traffic. The firewall is configured to log only denied traffic. What is the most likely issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.