
Certified Tester Security Test Engineer
Domain 9Objective 2
Black-Box Security Test Tools CT-STE Practice Questions (Page 3)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
Questions 11–15
- 11
What is a common limitation of black-box security test tools?
Select an answer first - 12
A penetration tester is assessing a web application that uses both a REST API and a traditional HTML form-based interface. The tester wants to automate the discovery of common web vulnerabilities such as XSS and CSRF across both interfaces. Which tool category is most suitable?
Select an answer first - 13
What is the primary role of fuzzers in black-box security testing?
Select an answer first - 14
How does a vulnerability scanner typically identify potential vulnerabilities in a black-box test?
Select an answer first - 15
What is the primary purpose of black-box security test tools in the context of security testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.