
Certified Tester Security Tester
Domain 1Objective 8
People, Process and Technology CT-SEC Practice Questions (Page 6)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
4concepts
Questions 26–27
- 26
A security tester is testing a web application that uses a database to store user credentials. The tester wants to check if the application is vulnerable to SQL injection. Which technology is most appropriate for this test?
Select an answer first - 27
A security team is planning to test a critical legacy system that cannot be taken offline. The system is running on outdated hardware and software. The team has a limited budget and must choose between using an automated scanner or performing manual testing. The team is experienced in manual testing but has no experience with the specific scanner. Which approach is most appropriate?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.