
Certified Tester Security Tester
Domain 3Objective 1
Security Testing Process Overview CT-SEC Practice Questions (Page 4)
Part of the Security Testing Processes domain, which makes up ~9% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
2concepts
Questions 16–20
- 16
A security tester is in the design phase of a security test. They have identified the security objectives and risks during planning. What should they do to create effective security test cases?
Select an answer first - 17
A security tester is conducting a security test for a critical application. During the planning phase, they identify that the application handles personally identifiable information (PII) and is subject to GDPR. They also note that the application is developed using a DevOps model with frequent releases. How should the tester incorporate GDPR requirements into the security testing process?
Select an answer first - 18
Which activity is part of the security test execution phase in the ISTQB security testing process?
Select an answer first - 19
A DevOps team wants to integrate security testing into their CI/CD pipeline. They have a mix of automated SAST and DAST tools, but they are concerned about the high number of false positives. They also need to ensure that critical vulnerabilities are not missed. How should they adapt the ISTQB security testing process to address this challenge?
Select an answer first - 20
During the execution phase of a security test, a tester discovers a critical vulnerability that could allow an attacker to access sensitive customer data. According to the ISTQB security testing process, what should the tester do FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.