
Certified Tester Security Tester
Domain 3Objective 3
Security Test Design CT-SEC Practice Questions (Page 4)
Part of the Security Testing Processes domain, which makes up ~9% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 16–20
- 16
What is the primary purpose of attack surface analysis in security test design?
Select an answer first - 17
A security tester is planning the testing effort for a new application. The application has a large attack surface, but the testing budget is limited. The tester must decide which parts of the application to test first. Which approach BEST aligns with the principle of risk-based testing?
Select an answer first - 18
A tester is designing security tests for a legacy application that is being migrated to the cloud. The application has a known critical vulnerability that cannot be patched in the current release. The business has decided to accept the risk for the next quarter. The tester has a limited budget for security testing. What is the MOST appropriate action for the tester?
Select an answer first - 19
Which principle is fundamental to risk-based security testing?
Select an answer first - 20
A security tester is designing test cases for a new mobile application that stores data locally on the device. The tester has identified a risk of sensitive data exposure if the device is lost or stolen. Which test case is MOST directly aligned with this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.