
Certified Tester Security Tester
Domain 7Objective 1
Security Test Evaluation CT-SEC Practice Questions (Page 4)
Part of the Security Test Evaluation and Reporting domain, which makes up ~6% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
8concepts
Questions 16–20
- 16
A security test reveals that a web application is vulnerable to Server-Side Request Forgery (SSRF). The tester traces the vulnerability to a feature that fetches URLs provided by users. The application has a firewall that blocks requests to internal IP addresses. However, the tester successfully exploits the SSRF by using a redirect from an external URL to an internal IP. What is the root cause of the vulnerability?
Select an answer first - 17
A company has a web application protected by a Web Application Firewall (WAF) that blocks common SQL injection patterns. A penetration test finds that the WAF can be bypassed using a specific encoding technique, and the tester successfully extracts data from the database. The WAF is the only security control for this application. What should the evaluation conclude about the effectiveness of the WAF?
Select an answer first - 18
A security tester completes a web application scan and finds a 'SQL Injection in login parameter' alert. The tester manually verifies the payload and confirms the database error message appears, but the application uses parameterized queries and the error is a generic custom message. The tester also notices the scanner flagged the same issue on 15 other parameters with identical evidence. What should the tester do with these findings?
Select an answer first - 19
A security test evaluation is being conducted for a new application. The evaluation team has a limited budget and must decide whether to use an automated scanner, manual testing, or a combination. The application is a small internal tool with limited functionality, but it handles sensitive data. The team wants to minimize false positives while ensuring thorough coverage. What is the most appropriate approach?
Select an answer first - 20
What is the primary purpose of prioritizing security findings?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.