
Certified Tester Security Test Engineer
Domain 8Objective 4
Avoid Vulnerability CT-STE Practice Questions (Page 2)
Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
Questions 6–10
- 6
What is the primary goal of threat modeling in the context of vulnerability avoidance?
Select an answer first - 7
A security architect is leading a threat modeling workshop for a new payment processing system. The system will handle cardholder data and must comply with PCI DSS. During the workshop, the team identifies that the system will accept input from a public-facing web form. Which threat modeling output is most directly useful for avoiding vulnerabilities in the input handling component?
Select an answer first - 8
A security tester discovers a buffer overflow vulnerability in a legacy C++ module. The module is scheduled for replacement in six months, but it is still in production. What is the most appropriate way to document this vulnerability to support its remediation?
Select an answer first - 9
What is a key characteristic of an effective vulnerability report?
Select an answer first - 10
A startup is developing a new web application and wants to integrate security testing early in the development process. They have a small team and limited budget. Which approach is most practical for them?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.