
Certified Tester Security Tester
Domain 1Objective 8
People, Process and Technology CT-SEC Practice Questions (Page 1)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
4concepts
Questions 1–5
- 1
Why is it important to have a defined process even when using advanced security testing tools?
Select an answer first - 2
A security tester is testing a network infrastructure and needs to identify open ports and services running on a target server. Which technology is most appropriate for this task?
Select an answer first - 3
A security team is implementing a new security testing program. The team has a limited budget and must choose between purchasing an expensive commercial vulnerability scanner or using open-source tools and investing in training for the team. The team is experienced but not familiar with the open-source tools. The organization values thorough testing and has a culture of continuous improvement. Which approach is most aligned with the principles of people, process, and technology?
Select an answer first - 4
A security tester is planning to test a new web application that is hosted in a cloud environment. The tester needs to ensure that the testing does not violate the cloud provider's terms of service. Which process step is essential before starting the test?
Select an answer first - 5
Which activity is typically performed during the 'reporting' phase of a security testing process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.