
Certified Tester Security Tester
Domain 4Objective 2
Requirements and Design CT-SEC Practice Questions (Page 1)
Part of the Security Testing Throughout the Software Lifecycle domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
9concepts
Questions 1–5
- 1
A product owner wants to add a feature that allows users to export their personal data in a machine-readable format. The security tester must ensure that security requirements are considered. Which requirement is most important to add?
Select an answer first - 2
After assessing security risks in requirements, what is the primary purpose of prioritizing them?
Select an answer first - 3
A company is developing a new customer support system. During requirements gathering, the team identifies several security requirements: encryption of customer data, role-based access control, and a public API for partners. The security tester must prioritize these requirements. Which requirement should be given the highest priority based on risk?
Select an answer first - 4
A design review is scheduled for a new customer relationship management (CRM) system. The security tester is part of the review team. Which activity is most aligned with a security-focused design review?
Select an answer first - 5
What does 'attack surface' refer to in security architecture analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.