Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 6Objective 2

Understanding the Attacker Mentality CT-SEC Practice Questions (Page 1)

Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts

Questions 1–5

  1. 1application · medium

    An attacker sends an email to an employee that appears to be from the IT helpdesk, stating that the employee's mailbox is over quota and they must click a link to 're-validate' their account. The link leads to a fake login page that captures the employee's credentials. Which human factor is the attacker primarily exploiting?

    Select an answer first
  2. 2application · medium

    A penetration tester is hired to assess a company's external perimeter. During the engagement, the tester spends significant time on LinkedIn and the company's career page, noting employee names, job titles, and technology mentions in job postings. The tester also reviews the company's DNS records and SSL certificate transparency logs. Which phase of the attacker's methodology is the tester primarily executing?

    Select an answer first
  3. 3foundation · easy

    What is the first step an attacker typically takes when planning an attack?

    Select an answer first
  4. 4expert · hard

    A security analyst is investigating a successful phishing attack. The email bypassed the email gateway and was delivered to a user's inbox. The user clicked a link and entered their credentials on a fake login page. The analyst discovers that the attacker used a newly registered domain that was very similar to the company's legitimate domain. Which control would have been most effective in preventing this specific attack?

    Select an answer first
  5. 5foundation · easy

    To mitigate the risk of phishing, which defensive approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.