
Certified Tester Security Tester
Domain 5Objective 4
Firewalls CT-SEC Practice Questions (Page 2)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
8concepts
Questions 6–10
- 6
A company is deploying a new firewall in an active-passive high availability pair. The security team wants to ensure that if the active firewall fails, the passive firewall takes over without dropping existing connections. Which feature must be configured to achieve this?
Select an answer first - 7
What is the primary goal of firewall bypass techniques such as tunneling and protocol evasion?
Select an answer first - 8
What is the primary purpose of regularly reviewing firewall policies?
Select an answer first - 9
A security tester is assessing a firewall that is configured to allow outbound HTTP and HTTPS. The tester wants to test if the firewall can be bypassed using protocol evasion. Which technique is most likely to succeed?
Select an answer first - 10
A security tester is reviewing a firewall policy for a small business. The policy includes the following rules: 1) allow tcp from any to any port 80; 2) allow tcp from any to any port 443; 3) allow udp from any to any port 53; 4) deny ip from any to any. The business only runs a public web server and needs DNS resolution for outbound traffic. Which rule is a potential security risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.