
Certified Tester Security Tester
Domain 5Objective 6
Malware Scanning CT-SEC Practice Questions (Page 3)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 11–15
- 11
A security tester is setting up a malware scanning test environment. The tester needs to ensure that the malware samples do not accidentally infect the host system or other network devices. Which configuration is most important to achieve this isolation?
Select an answer first - 12
A security tester needs to evaluate a new malware scanner's ability to detect polymorphic malware. The tester has a set of known malware samples that are all static, non-mutating files. Which approach best addresses the limitation of using only static samples?
Select an answer first - 13
A tester is analyzing the results of a malware scan. The scanner reported 10 files as malicious, but after manual analysis, the tester determines that 3 of the files are actually benign. What is the most appropriate action for the tester to take?
Select an answer first - 14
Which detection method is most effective at identifying previously unknown (zero-day) malware?
Select an answer first - 15
What is a recommended recommendation to improve malware scanning effectiveness based on test findings?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.