
Certified Tester Security Tester
Domain 3Objective 3
Security Test Design CT-SEC Practice Questions (Page 2)
Part of the Security Testing Processes domain, which makes up ~9% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 6–10
- 6
An organization's security policy states that all database connections from application servers must use encrypted protocols. A security tester is designing a test to verify this. Which test would provide the MOST direct evidence of compliance?
Select an answer first - 7
A security tester has a limited testing window and must choose which of three newly discovered vulnerabilities to test first. The tester has the following data: Vulnerability A has a high CVSS score but is only exploitable by an authenticated user with low privileges. Vulnerability B has a medium CVSS score but is remotely exploitable without authentication. Vulnerability C has a low CVSS score but affects a system that processes payment card data. According to risk-based testing principles, which vulnerability should the tester prioritize?
Select an answer first - 8
Which technique is used to systematically identify potential threats and vulnerabilities during security test design?
Select an answer first - 9
A security tester is creating a test plan for a new application. The tester has identified that the application uses a third-party library with a known critical vulnerability. The library is used in a feature that is only accessible to authenticated users. According to risk-based testing, how should the tester prioritize this issue?
Select an answer first - 10
A security tester is designing tests for a new customer-facing web application. The team has identified that the application accepts file uploads from unauthenticated users and that the upload directory is web-accessible. Which security test design technique would MOST directly help the tester identify the specific attack vectors to prioritize for this feature?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.