
Certified Tester Security Tester
Domain 5Objective 6
Malware Scanning CT-SEC Practice Questions (Page 5)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 21–25
- 21
After scanning a directory of 1,000 files with a malware scanner, the tool reports 15 files as malicious. The tester knows that 10 of the files are actually benign but have been packed with a common packer. What is the most appropriate interpretation of these results?
Select an answer first - 22
A security tester is comparing two malware scanners. Scanner A uses signature-based detection only, while Scanner B uses both signature-based and heuristic detection. In a test with a set of known malware samples, Scanner A detects 90% and Scanner B detects 95%. However, Scanner B also flags 10% of benign files as malicious. What is the most likely reason for the difference in detection rates?
Select an answer first - 23
In a malware scan report, what does a false positive indicate?
Select an answer first - 24
A security tester is setting up a malware scanning test environment. The tester needs to test the scanner's ability to detect malware in email attachments. The test environment is isolated from the internet. How should the tester obtain the malware samples?
Select an answer first - 25
What is a common limitation of signature-based malware scanners?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.