
Certified Tester Security Tester
Domain 7Objective 1
Security Test Evaluation CT-SEC Practice Questions (Page 2)
Part of the Security Test Evaluation and Reporting domain, which makes up ~6% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
8concepts
Questions 6–10
- 6
A security test evaluation is being planned for a critical application. The evaluation's purpose is to determine whether the application's security controls are effective and to identify any residual risk. The evaluation team has limited time and budget. What is the most appropriate scope for this evaluation?
Select an answer first - 7
In risk-based evaluation, what two factors are primarily used to assess the risk of a vulnerability?
Select an answer first - 8
A security assessment identifies a vulnerability in a public-facing web server that allows an attacker to enumerate valid usernames. The server is behind a load balancer that distributes traffic across multiple instances. The vulnerability is present in all instances. The company has a WAF that can be configured to block the enumeration attempts. What is the most appropriate risk-based recommendation?
Select an answer first - 9
A company has implemented a Security Information and Event Management (SIEM) system to detect and alert on security incidents. The SIEM generates a high volume of alerts, many of which are false positives. The security team is overwhelmed and has started to ignore alerts. A penetration test finds that a real attack was not detected by the SIEM because the attack pattern was not included in the correlation rules. What is the most appropriate evaluation of the SIEM's effectiveness?
Select an answer first - 10
A security tester needs to report a critical vulnerability to the CISO, who is not technical. The vulnerability is a remote code execution in a web application that could allow an attacker to take over the server. The CISO needs to understand the business impact and the urgency of remediation. What is the most effective way to communicate this finding?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.