Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 7Objective 1

Security Test Evaluation CT-SEC Practice Questions (Page 6)

Part of the Security Test Evaluation and Reporting domain, which makes up ~6% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
8concepts

Questions 26–30

  1. 26application · medium

    A security tester needs to report the results of a penetration test to a mixed audience: the CISO, the development team, and the IT operations team. The report must be clear and actionable for all stakeholders. What is the most effective approach?

    Select an answer first
  2. 27application · medium

    A security assessment finds that multiple user accounts have been compromised. The investigation reveals that all affected users had weak passwords and that the application does not enforce account lockout after multiple failed attempts. The tester also finds that the application logs authentication failures but does not alert on them. What is the most likely root cause of the account compromises?

    Select an answer first
  3. 28foundation · easy

    What is a false positive in security testing?

    Select an answer first
  4. 29foundation · easy

    Why is likelihood an important factor in risk-based evaluation?

    Select an answer first
  5. 30foundation · easy

    What is the primary purpose of security test evaluation within the overall testing process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CT-SEC

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.