
Certified Tester Security Tester
Domain 1Objective 6
Purpose of a Security Audit CT-SEC Practice Questions (Page 5)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
Questions 21–25
- 21
What is the primary difference between a security audit and a security assessment?
Select an answer first - 22
A mid-sized company is preparing for an ISO 27001 certification. Management wants an independent evaluation of its information security management system (ISMS) before the formal certification audit. The company's internal security team has deep knowledge of the systems but lacks certification experience. What is the most appropriate approach?
Select an answer first - 23
An audit team is in the process of gathering evidence for a security audit. The team is reviewing access control lists, interviewing system administrators, and examining security incident logs. Which phase of the audit process is the team currently in?
Select an answer first - 24
A company's management is concerned about the overall security posture and wants a comprehensive evaluation of its security controls, policies, and procedures. The goal is to identify weaknesses and verify that the implemented controls are effective. Which activity best meets this need?
Select an answer first - 25
Which of the following is a typical deliverable of a security audit?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.