
Certified Tester Security Tester
Domain 4Objective 4
System, Acceptance, and Maintenance CT-SEC Practice Questions (Page 5)
Part of the Security Testing Throughout the Software Lifecycle domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
3concepts
Questions 21–23
- 21
A company is in the acceptance testing phase for a new customer portal. The contract requires that the portal be compliant with GDPR. The user acceptance team has tested the functionality, but the security team is concerned about data privacy. What should the security testers do to ensure GDPR compliance is validated?
Select an answer first - 22
A company is planning to decommission an old application that stores sensitive data. The maintenance team is responsible for the decommissioning process. What security testing activity should be performed?
Select an answer first - 23
A company is developing a new application that will process sensitive customer data. The project is behind schedule, and the project manager proposes to skip security testing during system testing and rely on acceptance testing to catch any issues. What should the security testers advise?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-SEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.