Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 5Objective 8

Security Training CT-SEC Practice Questions (Page 7)

Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
9concepts

Questions 31–35

  1. 31application · medium

    A software company's security team launched a new training program. After the first quarter, the team reports that 95% of employees completed the course and the average quiz score was 92%. However, a subsequent internal assessment showed that employees still frequently reuse passwords across work and personal accounts. Which objective of the security training program is most clearly NOT being met?

    Select an answer first
  2. 32expert · hard

    A security analyst is reviewing the results of a training assessment. The data shows that the IT department scored 95% on the technical quiz, but the finance department scored 70%. However, the finance department has a much lower simulated phishing click rate (5%) than the IT department (15%). What is the MOST LIKELY explanation for this discrepancy?

    Select an answer first
  3. 33foundation · medium

    Which of the following is a quantitative metric for measuring security training effectiveness?

    Select an answer first
  4. 34application · medium

    A security manager has just completed a simulated phishing campaign. The overall click rate was 8%, which is below the industry average of 15%. However, the click rate in the finance department was 25%, while the marketing department was 3%. The manager needs to report on the effectiveness of the training. Which metric provides the MOST actionable insight for improving the program?

    Select an answer first
  5. 35application · medium

    A company's CISO wants to move beyond simple compliance and create a culture where employees actively think about security. The current training is a mandatory annual e-learning module that most employees complete quickly. The CISO wants to change the objective of the training program. Which shift in focus BEST aligns with the goal of creating a security-conscious culture?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CT-SEC

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.