
Certified Tester Security Tester
Domain 2Objective 1
Foundations of Security Testing CT-SEC Practice Questions (Page 1)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
4concepts
Questions 1–5
- 1
A startup is developing a new mobile app and has limited budget for security testing. The CEO wants to ensure that the app is secure but is unsure how to prioritize security testing efforts. Which approach best aligns security testing with the organization's business objectives?
Select an answer first - 2
A security tester is evaluating a new cloud-based application that will store sensitive customer data. The organization has a business objective to minimize costs, but also has a regulatory requirement to protect data at rest and in transit. The tester must decide which security testing activities to prioritize. Which approach best balances cost and regulatory requirements?
Select an answer first - 3
Which of the following is a primary goal of security testing?
Select an answer first - 4
A government agency is developing a new system that will handle classified information. The agency's security policy requires that all security testing be performed by cleared personnel and that the testing environment be isolated from the production network. Which organizational factor is most directly influencing the security testing approach?
Select an answer first - 5
A healthcare organization is preparing to launch a patient portal that will handle sensitive personal health information. The compliance team has mandated that security testing must demonstrate that the portal protects patient data confidentiality and integrity. The project manager asks the security tester to focus on finding vulnerabilities that could lead to unauthorized access or data tampering. Which primary goal of security testing is the team emphasizing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.