Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 2Objective 3

Security Testing Approaches and Stakeholders CT-SEC Practice Questions (Page 2)

Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
4concepts

Questions 6–10

  1. 6foundation · easy

    A security tester is asked to evaluate an application without any prior knowledge of its internal code, architecture, or design. Which security testing approach is being used?

    Select an answer first
  2. 7application · medium

    A security tester is asked to assess a legacy system that is no longer actively developed but is still in production. The tester has access to the source code and documentation. The main concern is to identify vulnerabilities that could be exploited by an external attacker. Which testing approach is most efficient for this scenario?

    Select an answer first
  3. 8application · medium

    A security test report includes a finding that a web application is vulnerable to cross-site scripting (XSS). The development team reviews the finding and argues that the affected input is only accessible to authenticated administrators, so the risk is low. The security tester disagrees. What is the most important factor in resolving this disagreement?

    Select an answer first
  4. 9foundation · easy

    In a security testing project, which stakeholder is primarily responsible for fixing the vulnerabilities that are identified during testing?

    Select an answer first
  5. 10foundation · easy

    A security team is deciding between black-box and white-box testing for a critical financial application. They need to identify vulnerabilities that are only visible in the code logic, such as insecure cryptographic implementations. Which approach is more appropriate for this goal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.