
Certified Tester Security Test Engineer
Domain 2Objective 3
Addressing Security Risks in Test Design CT-STE Practice Questions (Page 7)
Part of the Security Test Techniques domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
10concepts
Questions 31–34
- 31
A security requirement states: 'The application must prevent unauthorized access to user data.' The test team needs to derive measurable security test objectives. Which of the following is a measurable test objective?
Select an answer first - 32
A threat model identifies SQL injection as a primary threat to a web application. Which test technique would be most appropriate to tailor for this threat?
Select an answer first - 33
A threat model for an online banking application identified a threat of session fixation via URL parameters. The test team is designing security tests. Which test technique is most appropriate to address this specific threat?
Select an answer first - 34
A security risk is rated as high likelihood and high impact. According to risk-based test design, what is the most appropriate action?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-STE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.