
Certified Tester Security Tester
Domain 6Objective 7
Increasing Security Awareness CT-SEC Practice Questions (Page 5)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
4concepts
Questions 21–25
- 21
A security tester is working with a development team that has a strong culture of 'moving fast' and often deprioritizes security tasks as 'blockers'. The tester wants to improve the team's security awareness and get them to adopt secure practices. Which approach is most likely to succeed in this cultural context?
Select an answer first - 22
A security tester is assessing the human factors that could lead to a data breach. The tester interviews employees and finds that many are unaware of the organization's data classification policy and often send sensitive files to personal email accounts for convenience. What is the most significant human-factor risk demonstrated here?
Select an answer first - 23
A tester is working with a team that consistently delivers features on time but has a history of security issues found late in the release cycle. The tester wants to introduce security awareness to shift the team's focus earlier. Which action best applies security awareness principles to improve the testing process?
Select an answer first - 24
A tester is creating a security test plan for a new application. The tester wants to ensure that security awareness is applied throughout the testing process, not just in the final security test phase. Which approach best achieves this?
Select an answer first - 25
A security tester is performing a risk assessment and identifies that a critical application stores sensitive customer data. The tester finds that developers often use shared service accounts to access the production database for debugging, and these accounts have no individual accountability. What is the primary human-factor risk, and what is the most effective control to mitigate it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.