Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 4Objective 1

Lifecycle Overview CT-SEC Practice Questions (Page 1)

Part of the Security Testing Throughout the Software Lifecycle domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
4concepts

Questions 1–5

  1. 1application · medium

    A company is adopting a shift-left approach to security testing. Which change best exemplifies this approach?

    Select an answer first
  2. 2expert · hard

    A legacy application is being modernized. The team wants to introduce security testing but has limited resources. They must choose between performing threat modeling during design or conducting penetration testing after deployment. Which choice is more aligned with lifecycle security principles?

    Select an answer first
  3. 3expert · hard

    A project manager is comparing two projects: Project A performs security testing continuously throughout the lifecycle, while Project B performs security testing only at the end. Which statement best describes the expected outcome?

    Select an answer first
  4. 4application · medium

    After a web application has been in production for several months, a new critical vulnerability is disclosed. Which security activity is most appropriate during the maintenance phase?

    Select an answer first
  5. 5foundation · easy

    What is a primary benefit of shift-left security testing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.