
Certified Tester Security Tester
Domain 2Objective 1
Foundations of Security Testing CT-SEC Practice Questions (Page 2)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
4concepts
Questions 6–10
- 6
A multinational corporation is implementing a new customer relationship management (CRM) system. The system will store personal data of customers in multiple countries, including the European Union (EU) and the United States. The EU's General Data Protection Regulation (GDPR) requires that personal data of EU citizens be protected, and the company's internal policy requires that all security testing be performed by an internal team. The security testing team is planning the scope of testing. Which approach best balances the regulatory requirements and the internal policy?
Select an answer first - 7
A security tester is explaining to a developer why security testing is important even though the organization has implemented information assurance measures. Which statement best explains the relationship?
Select an answer first - 8
A software development team is integrating security testing into their agile process. The team lead wants to ensure that security testing is not just a final phase but is woven throughout the development lifecycle. Which approach best reflects the role of security testing within the overall software testing process?
Select an answer first - 9
A company is developing a new online payment system. The security team has identified that the system processes credit card data and is subject to PCI DSS requirements. The team is planning security testing to ensure that the system protects cardholder data. Which primary goal of security testing is most directly aligned with this planning?
Select an answer first - 10
A security manager is reviewing the organization's approach to protecting its information assets. The organization has implemented a comprehensive information assurance program that includes policies, risk management, and security controls. However, a recent security incident revealed a vulnerability that was not detected by the existing controls. The manager is considering how to prevent similar incidents. Which action best addresses the gap between information assurance and security testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.