
Certified Tester Security Tester
Domain 5Objective 1
System Hardening CT-SEC Practice Questions (Page 3)
Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
4concepts
Questions 11–15
- 11
A security tester is evaluating a server that hosts a critical application. The server was hardened six months ago, but since then, several new services have been installed by the application team. The tester must determine whether the server is still compliant with the hardening baseline. Which approach is MOST appropriate?
Select an answer first - 12
A security tester is verifying the effectiveness of a hardening baseline on a fleet of 200 identical Linux workstations. The tester previously ran a compliance scan and found that 95% of the systems passed. The tester now needs to determine whether the 5% that failed are due to configuration drift or due to an error in the baseline itself. Which approach would BEST distinguish between these two causes?
Select an answer first - 13
A security tester is explaining to a colleague why system hardening is important even for systems that are not directly exposed to the internet. Which reason BEST justifies hardening internal systems?
Select an answer first - 14
A security tester is assessing a server that runs a critical application. The server has a known vulnerability in the application software, but the vendor has not yet released a patch. The tester discovers that the application is running with administrative privileges, which increases the impact of a potential exploit. The tester must recommend a mitigation. Which recommendation is MOST appropriate?
Select an answer first - 15
A security tester is reviewing the hardening of a new application server. The server was configured using a security baseline, but the tester notices that the baseline does not include a setting to disable USB storage devices. The organization's policy requires that USB storage be disabled on all servers. What should the tester do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.