
Certified Tester Security Test Engineer
Domain 8Objective 4
Avoid Vulnerability CT-STE Practice Questions (Page 3)
Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
Questions 11–15
- 11
Which of the following is an example of a security requirement that supports vulnerability avoidance?
Select an answer first - 12
Which activity is an example of integrating security testing into an early phase of development?
Select an answer first - 13
Why is it important to document vulnerabilities in a centralized repository?
Select an answer first - 14
Which vulnerability type is characterized by an attacker injecting malicious scripts into web pages viewed by other users?
Select an answer first - 15
A security tester is reviewing a Java web application that constructs SQL queries by concatenating user input directly into the query string. Which vulnerability is most likely present, and what is the most effective avoidance strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.