
Certified Tester Security Test Engineer
Domain 8Objective 4
Avoid Vulnerability CT-STE Practice Questions (Page 4)
Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
Questions 16–20
- 16
Which of the following is a common characteristic of an SQL injection vulnerability?
Select an answer first - 17
During a security review, a tester identifies that a web application does not validate the length of user input before storing it in a database. The tester notes that an attacker could exploit this to cause a denial-of-service condition by submitting extremely long strings. How should the tester classify this finding?
Select an answer first - 18
A development team is using a DevOps model with frequent releases. They want to ensure that security testing is integrated early and continuously. Which approach best achieves this?
Select an answer first - 19
What is the primary purpose of security requirements analysis in the context of vulnerability avoidance?
Select an answer first - 20
A security tester finds a vulnerability in a web application that allows an attacker to read arbitrary files on the server. The tester needs to document this finding so that developers can reproduce and fix it. Which information is most critical to include in the vulnerability report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.