
Certified Tester Security Tester
Domain 1Objective 6
Purpose of a Security Audit CT-SEC Practice Questions (Page 4)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
Questions 16–20
- 16
A security team is asked to evaluate the organization's compliance with internal security policies and identify areas for improvement. The team plans to compare current practices against the policies and produce a report with recommendations. However, the team is also asked to actively test the effectiveness of the controls by attempting to bypass them. Which approach best combines these requirements?
Select an answer first - 17
Which statement best describes a security audit?
Select an answer first - 18
During a security audit, the auditor discovers that a system administrator has been bypassing the change management process to apply urgent security patches. The administrator argues that this is necessary to protect the systems. The auditor is concerned about the lack of documentation. What is the most appropriate action for the auditor to take?
Select an answer first - 19
After completing a security audit, the audit team has identified several critical vulnerabilities in the organization's network infrastructure. The team has documented the findings and is now preparing to communicate the results to management. What is the most important deliverable to produce at this stage?
Select an answer first - 20
Who is typically responsible for ensuring that audit findings are addressed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.