
Certified Tester Security Tester
Domain 2Objective 4
Improving Security Testing Practices CT-SEC Practice Questions (Page 1)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
1concept
Questions 1–5
- 1
A security team is integrating security testing into a CI/CD pipeline. They want to catch vulnerabilities early without slowing down development. Which approach best achieves this goal?
Select an answer first - 2
What is a key benefit of establishing a feedback loop between security testing and development teams?
Select an answer first - 3
A security testing team is evaluating the effectiveness of their testing program. They have data on the number of vulnerabilities found, but they want to know if the program is actually reducing risk. Which metric would be most useful for this purpose?
Select an answer first - 4
A security testing team is planning the next penetration test. They have limited time and budget. Which approach would most effectively use their resources?
Select an answer first - 5
A security testing team is testing a mobile application that stores sensitive user data on the device. The team has identified a vulnerability that requires physical access to the device to exploit. The client wants to know if this is a high-risk issue. What should the team consider?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.