
Certified Tester Security Tester
Domain 4Objective 4
System, Acceptance, and Maintenance CT-SEC Practice Questions (Page 1)
Part of the Security Testing Throughout the Software Lifecycle domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 1–5
- 1
How does security testing integrate with functional and non-functional testing during system testing?
Select an answer first - 2
A company is planning to upgrade the database management system (DBMS) for a critical application. The upgrade changes the default encryption algorithms. What should the security testers do as part of the maintenance testing?
Select an answer first - 3
What is the purpose of impact analysis in the context of security testing during software maintenance?
Select an answer first - 4
A software maintenance team is about to apply a security patch to a web application that handles user authentication. The patch modifies the session management module. What should the team do to ensure the change does not introduce new vulnerabilities?
Select an answer first - 5
A company is in the user acceptance testing phase for a new HR system. The system must allow employees to view their own salary information but not others'. The user acceptance team is testing this functionality. What is the security tester's role in this phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.