
Certified Tester Security Tester
Domain 1Objective 6
Purpose of a Security Audit CT-SEC Practice Questions (Page 6)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
Questions 26–30
- 26
A company has conducted security audits for the past three years. Each audit has identified similar findings, but management has not implemented the recommendations. The security team is frustrated and wants to ensure that the audits lead to actual improvements. What is the most effective way to achieve this?
Select an answer first - 27
During a security audit, the auditor requests access to the organization's network diagrams and firewall configuration files. The system administrator responsible for these systems is hesitant to provide them, citing confidentiality concerns. Who is primarily responsible for ensuring the auditor receives the necessary information?
Select an answer first - 28
A financial services company must demonstrate to its regulator that its customer data handling practices align with the Payment Card Industry Data Security Standard (PCI DSS). The compliance officer asks the security team to conduct an evaluation that produces documented evidence of conformity. Which action best fulfills this request?
Select an answer first - 29
What is the primary purpose of a security audit?
Select an answer first - 30
What is included in the findings section of an audit report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.