
Certified Tester Security Test Engineer
Domain 7Objective 1
Acceptance Criteria for Security Testing CT-STE Practice Questions (Page 6)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
Questions 26–29
- 26
A security test team is defining acceptance criteria for a new web application. The organization has a risk assessment that identifies SQL injection as a high risk. Which source should they use to define criteria related to SQL injection?
Select an answer first - 27
Which of the following is a valid source of acceptance criteria for security testing?
Select an answer first - 28
What is a key requirement for writing unambiguous acceptance criteria?
Select an answer first - 29
A security test team is reviewing acceptance criteria for a new web application firewall (WAF). Which criterion is the most testable?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-STE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.