Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 2Objective 1

Black-Box, White-Box and Grey-Box Security Testing CT-STE Practice Questions (Page 2)

Part of the Security Test Techniques domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
6concepts

Questions 6–10

  1. 6expert · hard

    A security test engineer is assessing a web application that has a complex business logic layer. The organization has the source code but is concerned about the time required for a full white-box assessment. They want to balance thoroughness with efficiency. Which approach is most appropriate?

    Select an answer first
  2. 7foundation · easy

    In which scenario is black-box security testing most appropriate?

    Select an answer first
  3. 8expert · hard

    A security test engineer is planning a security assessment for a cloud-based application that processes sensitive customer data. The organization has strict compliance requirements and wants to ensure that the testing approach does not expose sensitive data to the testers. They have access to the source code but are concerned about data privacy. Which testing approach is most appropriate?

    Select an answer first
  4. 9application · medium

    A security test engineer is assessing a critical financial application. The organization has provided full access to the source code, database schema, and internal architecture diagrams. The goal is to identify vulnerabilities that could lead to unauthorized transactions. Which testing approach is most effective?

    Select an answer first
  5. 10expert · hard

    A security test engineer is leading a security assessment for a legacy system that is being decommissioned. The organization wants to identify all critical vulnerabilities before the system is retired, but the budget is limited and the source code is available. The team has only two weeks to complete the assessment. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.