
Certified Tester Security Tester
Domain 6Objective 4
Understanding Attack Scenarios and Motivations CT-SEC Practice Questions (Page 2)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
4concepts
Questions 6–10
- 6
Which scenario best describes a pretexting attack?
Select an answer first - 7
What is the primary impact of human factors on the success of a security attack?
Select an answer first - 8
An attacker impersonates a senior manager to request sensitive information from an employee. Which human factor is being exploited?
Select an answer first - 9
A security tester is conducting a social engineering assessment for a company that has a strong security culture. The tester wants to test the effectiveness of the company's security awareness training. Which approach would provide the most accurate assessment of the training's impact on human factors?
Select an answer first - 10
After a security awareness training session, a company runs a simulated phishing campaign. The results show a 20% click rate. The security team wants to measure the impact of the training on human factors. Which metric would best indicate the training's effectiveness?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.