
Certified Tester Security Tester
Domain 2Objective 3
Security Testing Approaches and Stakeholders CT-SEC Practice Questions (Page 1)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
Questions 1–5
- 1
A security team must test a critical financial application. They have full access to the source code and architecture documentation, but they also want to ensure that the test reflects real-world attack scenarios. Which approach best balances thoroughness and realism?
Select an answer first - 2
During a security test, a scanner reports a critical vulnerability in a web application. Upon manual verification, the tester determines that the vulnerability does not actually exist because the application properly sanitizes the input. What type of security testing failure does this scenario illustrate?
Select an answer first - 3
In a security testing project, which stakeholder is most likely to be concerned with the business impact of a vulnerability, such as the cost of a data breach or regulatory fines?
Select an answer first - 4
A security test is performed on a web application, but the test only covers the login functionality and does not test the file upload feature. As a result, a serious vulnerability in the file upload feature is not discovered. Which security testing failure does this scenario illustrate?
Select an answer first - 5
A security tester has full access to the source code, architecture diagrams, and internal documentation of an application. Which security testing approach does this scenario describe?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.