
Certified Tester Security Tester
Domain 9Objective 3
Selection of Security Standards CT-SEC Practice Questions (Page 1)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
3concepts
Questions 1–5
- 1
A company is considering implementing a security standard but is concerned about the cost and complexity of full certification. The company wants to improve its security posture without committing to a full certification process. Which approach is most appropriate?
Select an answer first - 2
A software development company builds web applications and wants to integrate security testing into its CI/CD pipeline. The team needs a standard that provides detailed, testable requirements for web application security. Which standard should they select?
Select an answer first - 3
A company is required by a client to demonstrate that it has implemented a set of security controls. The company is not required to obtain a formal certification but must provide evidence of its security practices. Which standard is most appropriate for this purpose?
Select an answer first - 4
Which of the following standards is best described as focusing on establishing and maintaining an information security management system (ISMS)?
Select an answer first - 5
A company is in the early stages of developing a security program and needs a standard that provides a structured approach to identifying, assessing, and managing cybersecurity risk. The company also wants to align with industry best practices. Which standard is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.