
Certified Tester Security Test Engineer
Domain 9Objective 2
Black-Box Security Test Tools CT-STE Practice Questions (Page 2)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
Questions 6–10
- 6
A security team is testing a web application that uses a JavaScript-heavy single-page application (SPA) framework. A web application scanner reports no vulnerabilities, but the team suspects the scanner is missing issues because it cannot execute JavaScript. What is the most appropriate action?
Select an answer first - 7
Which tool is a network-based black-box security tool used to discover hosts and open ports on a network?
Select an answer first - 8
A developer is testing a web application that uses a REST API with OAuth2 authentication. The developer wants to automate the testing of authorization flaws, such as IDOR (Insecure Direct Object References). Which tool feature is most important?
Select an answer first - 9
How do fuzzers generate inputs to test a target application?
Select an answer first - 10
A fuzzing campaign on a file parser has produced thousands of crashes. The team has limited time to triage them. Which approach is most efficient for prioritizing which crashes to investigate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.