
Certified Tester Security Tester
Domain 1Objective 7
Risk Identification, Assessment and Mitigation CT-SEC Practice Questions (Page 4)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
4concepts
Questions 16–20
- 16
What is the primary purpose of risk assessment in security testing?
Select an answer first - 17
A security team is managing risks for a cloud-based application. They have identified a risk of unauthorized access to customer data due to misconfigured cloud storage. The team has implemented encryption and access controls, but the risk is still not fully mitigated. What additional step should the team take?
Select an answer first - 18
A security tester identifies a risk in a web application where user input is not properly sanitized, leading to a SQL injection vulnerability. The organization's risk appetite is moderate. Which mitigation strategy is the most effective in reducing the risk?
Select an answer first - 19
A security tester needs to communicate the results of a risk assessment to a non-technical project sponsor. What is the most effective approach?
Select an answer first - 20
A security tester is evaluating the risk of a phishing attack on employees. The likelihood of an employee falling for a phishing email is high, and the impact of a successful attack is moderate. The organization has a moderate risk appetite. What is the most appropriate risk treatment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.