Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 2Objective 1

Foundations of Security Testing CT-SEC Practice Questions (Page 3)

Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
4concepts

Questions 11–15

  1. 11application · medium

    A financial services company is subject to the Payment Card Industry Data Security Standard (PCI DSS) and must demonstrate compliance during an upcoming audit. The security testing team is planning the scope of their testing activities. Which organizational factor is most directly driving the scope and depth of the security testing?

    Select an answer first
  2. 12expert · hard

    A company is developing a new product that will be sold to government agencies. The government requires that the product meet specific security standards, and the company's internal policy requires that all security testing be completed before the product is released. The development team is behind schedule, and the project manager is considering skipping some security testing to meet the deadline. Which approach best balances the need to meet the deadline with the regulatory and internal policy requirements?

    Select an answer first
  3. 13foundation · easy

    Why do regulations and business objectives influence the approach to security testing?

    Select an answer first
  4. 14expert · hard

    A security tester is working on a project where the organization has a high tolerance for risk but is subject to strict regulatory requirements. The tester has identified a vulnerability that is not likely to be exploited but could lead to a regulatory violation if it were. The project manager wants to deprioritize the vulnerability because the risk of exploitation is low. Which action best aligns with the primary goals of security testing?

    Select an answer first
  5. 15foundation · easy

    What is the primary distinction between information assurance and security testing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.