
Certified Tester Security Tester
Domain 4Objective 2
Requirements and Design CT-SEC Practice Questions (Page 7)
Part of the Security Testing Throughout the Software Lifecycle domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
9concepts
Questions 31–35
- 31
A design for a new IoT system includes devices that communicate with a cloud backend via MQTT. The security tester is asked to apply design-level threat modeling. Which threat is most critical to address in this design?
Select an answer first - 32
A security test plan is being developed for a new application. The design includes a microservices architecture with an API gateway. The security tester must outline test objectives. Which objective is most appropriate to include?
Select an answer first - 33
A security design review is conducted for a new online payment system. The design includes a web application, a payment gateway, and a database. The security tester identifies a design flaw: the web application directly accesses the database with a privileged account. Which action is most appropriate for the security tester to take?
Select an answer first - 34
Which of the following is typically included in a security test plan?
Select an answer first - 35
What is the main objective of design-level threat modeling?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.