
Certified Tester Security Tester
Domain 2Objective 3
Security Testing Approaches and Stakeholders CT-SEC Practice Questions (Page 3)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
Questions 11–15
- 11
A security tester is evaluating a web application's API. The tester has access to the API documentation and knows the internal data model, but does not have the source code. The goal is to test for authorization flaws that might be exploited by a legitimate user. Which testing approach is most suitable?
Select an answer first - 12
A security test of a web application reveals a vulnerability that could allow an attacker to access other users' personal data. The development team is concerned about the effort required to fix it, and the business owner is concerned about the potential legal implications. The security testers are confident in the finding. What is the most appropriate way to proceed?
Select an answer first - 13
A security test reveals a critical vulnerability in a customer-facing application. The business owner wants to release the application on schedule to meet a market opportunity, but the security team recommends delaying the release to fix the vulnerability. The development team is concerned about the additional work. What is the most appropriate course of action?
Select an answer first - 14
A security tester is asked to evaluate a web application's authentication mechanism. The tester has no prior knowledge of the application's source code or internal architecture, but has valid credentials for a standard user account. The goal is to identify vulnerabilities that an external attacker could exploit. Which testing approach is most appropriate?
Select an answer first - 15
A security test of a web application uses both automated scanning and manual testing. The automated scanner reports a potential SQL injection in a search field, but manual testing shows that the input is properly sanitized. However, the manual tester also discovers a different SQL injection in the sort parameter that the scanner missed. What does this scenario illustrate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.