
Certified Tester Security Test Engineer
Domain 7Objective 1
Acceptance Criteria for Security Testing CT-STE Practice Questions (Page 5)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
Questions 21–25
- 21
What is the primary role of acceptance criteria in security testing?
Select an answer first - 22
A security test team has completed a vulnerability scan of a web application. The acceptance criterion was: 'No critical or high vulnerabilities may remain.' The scan found two high vulnerabilities. What should the team do to verify the acceptance criteria?
Select an answer first - 23
A security test team is about to execute a penetration test against a customer's web application. The customer has provided a set of acceptance criteria that includes 'The application must not allow unauthorized access to user data.' The test lead wants to ensure the criteria are verifiable. Which action best improves the acceptance criteria?
Select an answer first - 24
Why is alignment with security objectives important for acceptance criteria?
Select an answer first - 25
A security test team is preparing a test report. They have executed tests against acceptance criteria and have the results. What is the most appropriate way to report the results?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.