
Certified Tester Security Tester
Domain 2Objective 3
Security Testing Approaches and Stakeholders CT-SEC Practice Questions (Page 4)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
Questions 16–20
- 16
A security test of a web application uses an automated scanner that reports several high-severity vulnerabilities. The development team manually verifies each finding and finds that two are false positives, but one is a real vulnerability. The scanner also missed a critical vulnerability that was found during manual testing. What is the most significant limitation of relying solely on automated scanning?
Select an answer first - 17
An organization is considering gray-box testing for a web application. What is a primary strength of gray-box testing compared to black-box testing?
Select an answer first - 18
A security tester is planning a test for a new web application that will be publicly accessible. The tester has no internal knowledge and wants to identify as many vulnerabilities as possible from an external perspective. However, the tester is concerned about the time and effort required. Which approach is most appropriate?
Select an answer first - 19
A security test of a web application uses an automated scanner that reports a high-severity vulnerability. The development team argues that the vulnerability is not exploitable because the affected functionality is only accessible to authenticated administrators. The security tester disagrees and believes the vulnerability is still a risk. What is the most important factor in determining the actual risk?
Select an answer first - 20
A security tester is asked to test a new web application that will be publicly accessible. The tester has no internal knowledge, but the client has provided a valid user account for testing. The client wants to know if an external attacker could access other users' data. Which testing approach is most effective for this goal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.