
Certified Tester Security Tester
Domain 6Objective 1
The Impact of Human Behavior on Security Risks CT-SEC Practice Questions (Page 3)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 11–15
- 11
A security tester is reviewing password policies. The tester finds that many employees use the same password for their corporate accounts and personal social media. Which risk does this behavior primarily introduce?
Select an answer first - 12
A security tester is assessing the effectiveness of anti-phishing controls. The tester sends a phishing email that appears to be from a colleague, asking the recipient to review an attached document. The document contains a macro that installs malware. Which technique is the tester using?
Select an answer first - 13
What is the primary purpose of security awareness training?
Select an answer first - 14
An employee receives an email that appears to be from the CEO, urgently requesting the purchase of gift cards for a client and asking the employee to reply with the codes. The email address is slightly misspelled, but the employee complies without checking. Which social engineering technique is this an example of?
Select an answer first - 15
A company is planning to implement a security awareness training program. The goal is to reduce the risk of employees falling for phishing emails. Which training approach would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.