
Certified Tester Security Tester
Domain 1Objective 1
The Role of Risk Assessment in Security Testing CT-SEC Practice Questions (Page 2)
Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
8concepts
Questions 6–10
- 6
A security tester is performing a risk identification activity for a new mobile banking application. The tester needs to identify the assets, threats, and vulnerabilities relevant to the system. Which of the following is an example of a vulnerability?
Select an answer first - 7
What is the primary purpose of performing a risk assessment in the context of security testing?
Select an answer first - 8
A financial services company has a legacy internal application that processes non-critical, non-confidential reports. A risk assessment identifies a critical vulnerability in the application that would require a significant rewrite to fix. The application is scheduled for decommissioning in six months. Management decides not to fix the vulnerability and instead accepts the risk. How should the security testing team proceed?
Select an answer first - 9
A risk assessment identifies that an application's authentication mechanism has a high risk of brute-force attacks. Which test design is most aligned with this risk?
Select an answer first - 10
An organization decides to purchase cyber insurance to cover potential losses from a data breach. Which risk treatment option does this represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.