Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 1Objective 1

The Role of Risk Assessment in Security Testing CT-SEC Practice Questions (Page 5)

Part of the The Basis of Security Testing domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
8concepts

Questions 21–25

  1. 21application · medium

    After completing a security test, the testing team found a critical vulnerability in a customer-facing application. The vulnerability could allow unauthorized access to customer data. The team must report this to the stakeholders, who include both technical and non-technical members. What is the most effective way to communicate this finding?

    Select an answer first
  2. 22application · medium

    A risk assessment for an e-commerce platform identifies that the payment processing module has a high likelihood of a cross-site scripting (XSS) attack due to insufficient input validation. The impact is rated as high because it could lead to session hijacking and financial fraud. Which test design approach is most aligned with the risk assessment findings?

    Select an answer first
  3. 23foundation · easy

    Which of the following is a key element of effective risk communication to stakeholders?

    Select an answer first
  4. 24application · medium

    A security testing team has completed a risk assessment and identified several vulnerabilities in a web application. The team needs to communicate the findings to the executive board, which is primarily concerned with business impact. What is the most appropriate way to present the risk assessment findings?

    Select an answer first
  5. 25application · medium

    A software company is planning the security testing for a new customer-facing web application. The risk assessment identified two high-priority risks: SQL injection in the search feature and a denial-of-service (DoS) vulnerability in the file upload feature. The testing team has limited time and budget. What is the most appropriate way to plan the testing activities?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.