
Certified Tester Security Tester
Domain 7Objective 1
Security Test Evaluation CT-SEC Practice Questions (Page 5)
Part of the Security Test Evaluation and Reporting domain, which makes up ~6% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
8concepts
Questions 21–25
- 21
A penetration test reveals two vulnerabilities: (1) a reflected XSS in a public marketing site with no authentication, and (2) a stored XSS in an internal admin panel that requires a valid admin account. The marketing site has a high volume of visitors, while the admin panel is used by only five employees. Which vulnerability should be prioritized for remediation?
Select an answer first - 22
What is the purpose of root cause analysis in security testing?
Select an answer first - 23
A security assessment finds a vulnerability in a legacy application that is scheduled for decommissioning in six months. The vulnerability is a critical remote code execution (RCE) that requires authentication. The application is accessible only from the internal network, and the authentication is required for all users. The company has a compensating control: a network segmentation rule that restricts access to the application to a small group of administrators. What is the most appropriate risk-based recommendation?
Select an answer first - 24
Why is root cause analysis important for effective remediation?
Select an answer first - 25
What is a false negative in security testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.