
Certified Tester Security Test Engineer
Domain 2Objective 3
Addressing Security Risks in Test Design CT-STE Practice Questions (Page 5)
Part of the Security Test Techniques domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
10concepts
Questions 21–25
- 21
A risk is identified for a system, but no test case is linked to it. What does this indicate?
Select an answer first - 22
A security test engineer is defining coverage criteria for a web application that processes credit card payments. The risk analysis identified a high risk of SQL injection in the payment form. Which coverage criterion is most appropriate to ensure adequate testing of this risk?
Select an answer first - 23
What is the purpose of attack surface analysis in security testing?
Select an answer first - 24
A security test engineer is setting up a test environment for a web application that uses a third-party payment gateway. The test environment must be isolated from production, but the payment gateway is only available in the production environment. The engineer needs to test the integration with the gateway. What should the engineer do?
Select an answer first - 25
A security test engineer has a limited budget and must prioritize security tests for a web application. The risk analysis identified three risks: a high-likelihood, low-impact risk in the login page; a low-likelihood, high-impact risk in the admin panel; and a medium-likelihood, medium-impact risk in the API. Which risk should be tested first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.