
Certified Tester Security Tester
Domain 8Objective 1
Types and Purposes of Security Testing Tools CT-SEC Practice Questions (Page 1)
Part of the Security Testing Tools domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
14concepts
Questions 1–5
- 1
Which type of tool is used to assess and protect database systems?
Select an answer first - 2
Which type of tool is used to assess and monitor the security of network infrastructure?
Select an answer first - 3
Which type of tool is specifically designed to test mobile applications for vulnerabilities?
Select an answer first - 4
A SOC team is investigating a potential advanced persistent threat (APT) that may have been active for months. The team needs to reconstruct the timeline of the attack, including lateral movement and data exfiltration, using logs from multiple sources. The team also needs to preserve evidence for potential legal action. Which combination of tools should the team use?
Select an answer first - 5
A mobile app development team wants to test their Android application for insecure data storage and improper certificate validation. The team has both the source code and the compiled APK. They want to identify as many issues as possible before release, including those that only appear at runtime. Which approach should they take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.