
Certified Tester Security Tester
Domain 1Objective 7
Risk Identification, Assessment and Mitigation CT-SEC Practice Questions (Page 5)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
4concepts
Questions 21–24
- 21
Which of the following is an example of a risk mitigation strategy?
Select an answer first - 22
A company has a risk appetite that is low for any risk that could lead to a data breach. A security tester identifies a vulnerability that could lead to a data breach, but the likelihood of exploitation is very low. What is the most appropriate risk treatment?
Select an answer first - 23
A security tester has completed a risk assessment and needs to report the findings to the project manager. The project manager is not familiar with security terminology. What is the best way to present the risk information?
Select an answer first - 24
A security tester is performing a risk assessment for a new application. The tester has identified a vulnerability in the authentication mechanism. Which of the following is the most appropriate next step?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.