
Certified Tester Security Tester
Domain 3Objective 4
Security Test Execution and Evaluation CT-SEC Practice Questions (Page 4)
Part of the Security Testing Processes domain, which makes up ~9% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
6concepts
Questions 16–20
- 16
A security tester is running a penetration test against a web application. The tester is using a proxy tool to intercept and modify requests. Midway through the test, the tester notices that the proxy is not capturing any traffic from the application. The tester suspects the application is using certificate pinning. What is the most appropriate action?
Select an answer first - 17
A security analyst is analyzing the results of a vulnerability scan. The scanner reported a 'Cross-Site Scripting (XSS)' vulnerability in a comment field. The analyst manually tested the field with a standard XSS payload and the payload was executed in the browser. However, the analyst also noticed that the application uses a Content Security Policy (CSP) that should block inline scripts. The analyst is unsure if the vulnerability is real. What is the most appropriate next step?
Select an answer first - 18
A security test team has completed a penetration test against a critical internal application. The test objectives were to identify vulnerabilities that could lead to unauthorized data access. The team found several medium-severity vulnerabilities and one high-severity vulnerability. Management asks for a summary of the test's success. Which metric best demonstrates the test's success in meeting its objectives?
Select an answer first - 19
A penetration tester has completed a test and is writing the final report. The report includes a detailed technical description of a critical vulnerability, including the exact exploit code used. The report will be shared with both the development team and senior management. What is the most appropriate way to present this information?
Select an answer first - 20
When setting up a security test environment, why is it important to configure test data that is representative of production data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.