
Certified Tester Security Tester
Domain 6Objective 5
Social Engineering CT-SEC Practice Questions (Page 4)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
Questions 16–20
- 16
A company wants to reduce the risk of tailgating at its main entrance. The entrance currently has a security guard who checks badges visually, but employees often hold the door open for others. Which countermeasure would be MOST effective in preventing tailgating?
Select an answer first - 17
What should be included in a report of social engineering testing results?
Select an answer first - 18
Why is social engineering considered a relevant concern in security testing?
Select an answer first - 19
A security tester is crafting a phishing email for a client's assessment. The client wants to test the effectiveness of their security awareness training. The tester wants to maximize the likelihood of employees clicking the link. Which combination of psychological principles would be MOST effective?
Select an answer first - 20
A company wants to implement a countermeasure to reduce the risk of pretexting attacks over the phone. Which policy would be MOST effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.