
Certified Tester Security Tester
Domain 6Objective 4
Understanding Attack Scenarios and Motivations CT-SEC Practice Questions (Page 3)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
4concepts
Questions 11–15
- 11
A security tester is planning a social engineering assessment for a high-security research facility. The facility has strict access controls, including biometric scanners and security guards. The tester wants to gain physical access to the building. Which attack scenario is most likely to succeed given the human factors involved?
Select an answer first - 12
Which psychological principle is most directly exploited when an attacker creates a sense of urgency to make a victim act quickly without thinking?
Select an answer first - 13
Which attack scenario primarily relies on manipulating a user's trust in a familiar communication channel to trick them into revealing credentials?
Select an answer first - 14
A security tester is conducting a social engineering assessment. The tester sends a text message to an employee claiming they have won a gift card and need to verify their identity by providing their employee ID and date of birth. Which attack scenario is this?
Select an answer first - 15
A company experiences a successful phishing attack that bypasses email filters. The security team wants to assess the impact of human factors on the attack's success. Which measure would best help them understand the role of human behavior in this incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.