
Certified Tester Security Tester
Domain 6Objective 5
Social Engineering CT-SEC Practice Questions (Page 1)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
Questions 1–5
- 1
What is the primary characteristic of a tailgating attack?
Select an answer first - 2
What is a key ethical consideration when conducting social engineering tests as part of security testing?
Select an answer first - 3
A security tester is planning a social engineering test for a client. The tester wants to send phishing emails to employees, but the client is concerned about the potential for employees to become upset or to have their trust in the organization damaged. Which ethical consideration should the tester address in the test plan?
Select an answer first - 4
A security tester is planning a social engineering test for a client. The client wants to test the effectiveness of their security awareness training. Which testing technique would be MOST appropriate?
Select an answer first - 5
A security tester is conducting a social engineering assessment for a client. The tester has completed the test and is preparing the final report. The client asks the tester to include the names of employees who fell for the attacks so that they can be disciplined. Which action should the tester take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.