Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Tester

Domain 6Objective 2

Understanding the Attacker Mentality CT-SEC Practice Questions (Page 4)

Part of the Human Factors in Security Testing domain, which makes up ~14% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts

Questions 16–20

  1. 16expert · hard

    A security team is planning a tabletop exercise to test their incident response plan. The scenario is a ransomware attack. The team wants to ensure the exercise is realistic and tests their ability to respond to an attacker's actions. Which of the following injects (new information provided during the exercise) would best simulate the attacker's mindset and test the team's decision-making?

    Select an answer first
  2. 17application · medium

    An employee receives a phone call from someone claiming to be a vendor. The caller says they are updating their records and asks the employee to confirm their username and the last four digits of their employee ID. The employee provides the information. Which human factor is the attacker most directly exploiting?

    Select an answer first
  3. 18foundation · easy

    What is a primary goal of an attacker when probing a system for vulnerabilities?

    Select an answer first
  4. 19expert · hard

    A company's security team is investigating a data breach. They find that the attacker exfiltrated a large volume of source code and internal design documents, but did not encrypt any systems or demand a ransom. The attacker's actions were quiet and targeted, and the data was likely sold to a competitor. Which motivation best explains this attacker's behavior?

    Select an answer first
  5. 20application · medium

    A company is experiencing a rise in 'quishing' attacks, where QR codes in emails and physical posters are used to direct employees to malicious websites. Which combination of controls would most effectively mitigate this specific threat?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.