
Certified Tester Security Tester
Domain 3Objective 2
Security Test Planning CT-SEC Practice Questions (Page 5)
Part of the Security Testing Processes domain, which makes up ~9% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
4concepts
Questions 21–22
- 21
A security team is planning a test for a critical infrastructure system. The system has high availability requirements, and any downtime could have severe consequences. The team must decide between a full penetration test that requires a maintenance window and a limited test that can be performed during normal operations. The budget is sufficient for only one approach. What should the team do?
Select an answer first - 22
A security tester is planning a test that involves accessing sensitive customer data. The test plan includes a data handling procedure that specifies how data will be protected during the test. What is the primary reason for including this procedure in the plan?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.