
Certified Tester Security Tester
Domain 6Objective 1
The Impact of Human Behavior on Security Risks CT-SEC Practice Questions (Page 2)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 6–10
- 6
Which technique is a social engineering attack that relies on creating a sense of urgency to trick a victim into acting quickly?
Select an answer first - 7
A security tester is assessing a company's resilience to social engineering. The tester calls the help desk, pretends to be a new remote employee who forgot the onboarding password, and asks the help desk to reset it. The help desk agent, wanting to be helpful, resets the password without verifying the caller's identity. Which human factor is the tester primarily exploiting?
Select an answer first - 8
A company has experienced several successful phishing attacks despite having a security awareness training program. The training is a yearly, hour-long video that employees must watch. Which improvement would be most effective in reducing the risk?
Select an answer first - 9
Which scenario best illustrates a security risk caused by a lack of awareness rather than malicious intent?
Select an answer first - 10
A company wants to reduce the risk of data exfiltration by negligent insiders who accidentally email sensitive data to external parties. Which control would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.