Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 2Objective 3

Addressing Security Risks in Test Design CT-STE Practice Questions (Page 4)

Part of the Security Test Techniques domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
10concepts

Questions 16–20

  1. 16expert · medium

    A security test engineer is designing test data for a search feature that is vulnerable to SQL injection. The threat model indicates that the application uses parameterized queries, but the engineer wants to verify this. Which test data set is most effective for this purpose?

    Select an answer first
  2. 17application · medium

    A security test engineer is setting up a test environment to perform penetration testing on a web application. The environment must be isolated from the production network to prevent any impact on live systems. Which configuration is most appropriate?

    Select an answer first
  3. 18application · medium

    A security test engineer is documenting test cases for a new feature. The risk analysis identified a risk of cross-site scripting in the comment section. The engineer wants to ensure that the test case can be traced back to this risk. What should the engineer do?

    Select an answer first
  4. 19expert · medium

    A threat model for a healthcare application identified a threat of unauthorized data access via a broken access control in the API. The test team has limited time and must choose between two test approaches: performing a comprehensive access control test on the API or conducting a broader security test that includes other vulnerabilities. The risk analysis shows that broken access control is the highest risk. What should the test engineer do?

    Select an answer first
  5. 20foundation · easy

    Which of the following is an example of security test data that reflects a realistic attack pattern?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.