
Certified Tester Security Tester
Domain 3Objective 3
Security Test Design CT-SEC Practice Questions (Page 5)
Part of the Security Testing Processes domain, which makes up ~9% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 21–23
- 21
An organization's security standard requires that all administrative functions must be logged with the user ID, timestamp, and action performed. A security tester is designing a test to verify this. Which test would provide the MOST direct evidence of compliance?
Select an answer first - 22
What is the purpose of designing security tests based on organizational standards and procedures?
Select an answer first - 23
A security tester is designing tests for a web application that uses a third-party Single Sign-On (SSO) provider. The application also has a 'remember me' feature that stores a token in a cookie. The tester has identified a risk that the 'remember me' token could be stolen and used for session hijacking. Which of the following test cases would be MOST effective in validating this risk?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.