
Certified Tester Security Tester
Domain 2Objective 4
Improving Security Testing Practices CT-SEC Practice Questions (Page 3)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
1concept
Questions 11–15
- 11
Which strategy is most effective for improving the efficiency of security testing in an organization with limited resources?
Select an answer first - 12
A security testing team is responsible for testing a web application that handles sensitive customer data. The application is deployed in a cloud environment, and the team has access to the source code and the running application. They need to identify vulnerabilities that are specific to the cloud deployment, such as misconfigured storage and identity issues. Which testing approach would be most effective?
Select an answer first - 13
A security testing team is asked to test a new application that is being developed using a microservices architecture. The team has limited experience with this architecture. They need to ensure that the testing is thorough and covers the interactions between services. What is the best approach?
Select an answer first - 14
A security testing team is planning to test a legacy system that is critical to business operations. The system cannot be taken offline for testing. What is the best approach to test this system?
Select an answer first - 15
A security testing team is conducting a test of a critical infrastructure system. The test must not disrupt operations, but the team needs to test the system's response to a denial-of-service attack. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.