
Certified Tester Security Tester
Domain 5Objective 4
Firewalls CT-SEC Practice Questions (Page 3)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
8concepts
Questions 11–15
- 11
A security tester is performing firewall configuration testing. The firewall has a rule that allows inbound TCP port 443 from any source to a web server. The tester wants to verify that the firewall is not vulnerable to fragmentation attacks. Which test would be most effective?
Select an answer first - 12
Which firewall type is best suited to inspect the content of application-layer protocols, such as HTTP or SMTP, to block malicious payloads?
Select an answer first - 13
What is a key characteristic of an effective firewall logging and alerting mechanism?
Select an answer first - 14
Which type of firewall makes decisions based on the state of active connections, tracking the context of traffic flows rather than inspecting each packet in isolation?
Select an answer first - 15
In a screened subnet architecture, where is the firewall typically placed to create a buffer zone between the external network and the internal network?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.