
Certified Tester Security Tester
Domain 2Objective 2
Setting Security Testing Goals and Objectives CT-SEC Practice Questions (Page 4)
Part of the Security Testing Purposes, Goals and Strategies domain, which makes up ~7% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
Questions 16–20
- 16
When determining the scope of security testing, which of the following should be explicitly defined?
Select an answer first - 17
A security test team is testing a web application that handles personal data. The objective is to identify vulnerabilities that could lead to unauthorized access to personal data. The team has limited time. Which of the following best defines the coverage of this test?
Select an answer first - 18
A multinational corporation is subject to the EU's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). The security team is planning a test of a new customer data platform. The legal team requires that the test verify compliance with both regulations. The operations team is concerned about the test disrupting production systems. What should the security team do to align the test goals with these requirements?
Select an answer first - 19
A security test team is testing a new e-commerce website. The objective is to identify vulnerabilities that could lead to credit card theft. The website uses a third-party payment processor. The team has a limited budget and must decide on the coverage of the test. The payment processor claims to be PCI DSS compliant. What is the best approach?
Select an answer first - 20
A healthcare organization is preparing for a security test of its new patient portal. The compliance officer insists the test must verify that the portal meets GDPR requirements for data protection. The development team wants to focus on functional bugs. The security manager needs to balance these interests. What should the security manager do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.