Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 6Objective 4

Understanding Attack Scenarios and Motivations CT-SEC Practice Questions (Page 4)

Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
4concepts

Questions 16–20

  1. 16expert · hard

    A security consultant is assessing the threat landscape for a pharmaceutical company that develops a new COVID-19 vaccine. The company has received threats from hacktivist groups and also suspects industrial espionage. Which attacker motivation is most likely to result in a targeted attack on the vaccine research data?

    Select an answer first
  2. 17application · medium

    During a security test, an assessor leaves a USB drive labeled 'Confidential - Employee Bonuses' in the company parking lot. An employee picks it up and plugs it into their workstation, inadvertently installing malware. Which human psychological trait is being exploited?

    Select an answer first
  3. 18expert · hard

    A company has a high rate of successful phishing attacks despite regular security awareness training. The security team is considering implementing a technical control to reduce the impact of human error. Which control would be most effective in mitigating the consequences of a successful phishing attack?

    Select an answer first
  4. 19application · medium

    An attacker sends an email to an employee that appears to be from the IT department, stating that the employee's mailbox is full and they must click a link to increase their storage quota. The employee clicks the link and enters their credentials. Which human factor is primarily exploited?

    Select an answer first
  5. 20application · medium

    A security analyst notices a pattern of failed login attempts on a company's VPN, followed by a successful login from an unusual location. The attacker then accessed sensitive HR files. The analyst discovers the attacker used credentials obtained from a previous data breach. What is the most likely primary motivation of the attacker?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.