Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 5Objective 1

System Hardening CT-SEC Practice Questions (Page 4)

Part of the Testing Security Mechanisms domain, which makes up ~17% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
4concepts

Questions 16–20

  1. 16application · medium

    A security tester is verifying that a newly hardened server is compliant with the organization's security baseline. The tester runs a compliance scan and receives a report showing that 98% of the checks passed. The tester needs to determine whether the 2% that failed are significant. Which action should the tester take FIRST?

    Select an answer first
  2. 17expert · hard

    A security tester is evaluating a server that hosts a legacy application. The application requires an old version of a library that has a known critical vulnerability. The vendor no longer provides patches for this library, and the application cannot be updated without a major rewrite. The tester must recommend a course of action. Which recommendation BEST balances security and business continuity?

    Select an answer first
  3. 18expert · hard

    A security tester is assessing a web application server that is behind a load balancer. The server has a critical vulnerability in the web server software, but the load balancer is configured to block all traffic to the vulnerable endpoint. The tester must decide whether to prioritize patching this vulnerability. Which consideration is MOST important in this decision?

    Select an answer first
  4. 19foundation · easy

    Which of the following is a common system hardening technique that involves disabling or removing software components that are not needed for the system's intended function?

    Select an answer first
  5. 20application · medium

    A security tester is evaluating a newly deployed database server. The server has a default configuration, and the tester wants to verify that service minimization has been applied. Which finding would indicate that service minimization was NOT correctly implemented?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.