
Certified Tester Security Tester
Domain 3Objective 4
Security Test Execution and Evaluation CT-SEC Practice Questions (Page 5)
Part of the Security Testing Processes domain, which makes up ~9% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
6concepts
Questions 21–22
- 21
A security tester is conducting a penetration test on a web application. The test plan includes both automated scanning and manual testing. The automated scanner has completed its run and reported several potential vulnerabilities. The tester is now performing manual verification. During manual testing, the tester discovers a critical vulnerability that the scanner did not report. The tester also notices that the scanner's report includes a vulnerability that the tester cannot reproduce manually. The test is running behind schedule. What should the tester do?
Select an answer first - 22
What should a security test report include to be considered 'actionable'?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.