
Certified Tester Security Tester
Domain 4Objective 2
Requirements and Design CT-SEC Practice Questions (Page 5)
Part of the Security Testing Throughout the Software Lifecycle domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
9concepts
Questions 21–25
- 21
During requirements elicitation for a corporate document management system, the team identifies several security requirements: encryption of documents at rest, two-factor authentication for remote access, and a public sharing link feature. The security tester must prioritize these for implementation. Which approach best reflects security risk assessment in requirements?
Select an answer first - 22
A design for a new online learning platform includes a content delivery network (CDN), a web application, and a database. The security tester is asked to validate the design. Which action best validates that the architecture supports security requirements?
Select an answer first - 23
How does security testing inform design decisions?
Select an answer first - 24
Which artifact is most commonly used as input for design-level threat modeling?
Select an answer first - 25
How does security testing influence the requirements phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.