
Certified Tester Security Tester
Domain 9Objective 5
Where to Learn of Industry Trends in Information Security CT-SEC Practice Questions (Page 3)
Part of the Standards and Industry Trends domain, which makes up ~11% of our current practice bank. ISTQB does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
5concepts
Questions 11–15
- 11
A security testing team wants to adopt a new practice highlighted at a recent industry conference to improve the efficiency of their application security testing. The practice involves running automated security tests directly within the CI/CD pipeline to provide immediate feedback to developers. Which practice are they looking to adopt?
Select an answer first - 12
A security testing team is updating its methodology to align with a new industry trend that emphasizes 'security as code' and 'policy as code'. The team's goal is to ensure that security policies are automatically enforced and tested throughout the CI/CD pipeline. The team currently performs manual security reviews at the end of the development cycle. Which change would best align with this trend?
Select an answer first - 13
A security tester is updating the test plan for a healthcare organization. A new regulation has been introduced that requires more stringent security controls for electronic protected health information (ePHI). The tester must ensure that the test plan includes verification of these new controls. Which regulation is the tester primarily concerned with?
Select an answer first - 14
A security testing team is planning the annual test strategy for a large e-commerce platform. Industry reports indicate a rise in API-specific attacks, and the organization is adopting a microservices architecture with many internal APIs. The team has limited budget and must choose between expanding their existing DAST tool to cover APIs or investing in a new, specialized API security testing tool. The team's goal is to identify vulnerabilities in the new APIs before they are exploited. What is the most effective approach for the team to take?
Select an answer first - 15
Which of the following is an example of a recent emerging threat that has been widely reported by industry sources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-SEC” is a trademark of its owner, used for identification only.