
Certified Tester Security Tester
Domain 6Objective 2
Understanding the Attacker Mentality CT-SEC Practice Questions (Page 2)
Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
Questions 6–10
- 6
A security manager is reviewing the results of an internal phishing simulation. The results show that employees in the sales department clicked on a phishing email that offered a free gift card, while employees in the IT department were more likely to click on an email that warned of a security breach. Which conclusion best explains this difference in behavior?
Select an answer first - 7
A security team is designing a new employee onboarding process. They want to reduce the risk of an attacker using publicly available information to craft a convincing spear-phishing email. Which control best addresses this specific risk by limiting the information an attacker can gather?
Select an answer first - 8
A security architect is designing a defense strategy for a company that handles sensitive financial data. The architect knows that a sophisticated attacker will likely spend time studying the company's public-facing systems and employees before launching an attack. Which defensive strategy best reflects an understanding of this attacker mindset?
Select an answer first - 9
Which statement best describes the attacker mindset in security testing?
Select an answer first - 10
After successfully exploiting a vulnerability, what is a common next step in an attack plan?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.