
Certified Tester Security Tester
Domain 2Objective 4
Improving Security Testing Practices CT-SEC Practice Questions (Page 4)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
1concept
Questions 16–19
- 16
A security testing team has a limited budget and must choose between hiring an external penetration testing firm or investing in automated security testing tools. The team has skilled testers but lacks the time to perform manual testing. What should they consider to make the best decision?
Select an answer first - 17
A security testing team has been conducting penetration tests for the same web application every quarter for two years. The tests consistently find the same low-severity issues, but management is concerned that the team is not discovering new vulnerabilities. Which strategy would most effectively improve the security testing process?
Select an answer first - 18
A security testing team is reviewing the results of a recent test. They found several vulnerabilities that were also present in the previous test. What should they do to improve the testing process?
Select an answer first - 19
A security testing team is working with a development team that is resistant to security testing because they see it as slowing down their work. What should the security team do to improve collaboration?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.