
Certified Tester Security Tester
Domain 6Objective 1
The Impact of Human Behavior on Security Risks CT-SEC Practice Questions (Page 4)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 16–20
- 16
A security tester is evaluating the human factors that contribute to security risks. The tester observes that employees often leave their desks without locking their screens. Which risk does this behavior primarily introduce?
Select an answer first - 17
A company is implementing a new password policy. The security team wants to balance security with usability. Which policy is most effective in reducing risk while minimizing user frustration?
Select an answer first - 18
Which scenario is an example of a malicious insider threat?
Select an answer first - 19
What is the primary difference between phishing and pretexting?
Select an answer first - 20
A disgruntled employee who is about to be laid off copies a large amount of customer data to a personal USB drive before leaving. Which type of insider threat does this represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.