
Certified Tester Security Test Engineer
Domain 5Objective 4
Common Approach of a Hacker CT-STE Practice Questions (Page 3)
Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 11–15
- 11
A security analyst notices unusual outbound traffic from a workstation to an external IP address on port 4444. The analyst suspects the workstation is compromised. Which phase of the attack lifecycle does this observation most likely indicate?
Select an answer first - 12
A penetration tester is tasked with assessing the security of a company's external web application. The tester starts by using search engines to find cached versions of the application's pages and reviews the company's DNS records. The tester does not send any requests to the application itself. Which type of reconnaissance is the tester performing?
Select an answer first - 13
What is the purpose of enumeration in the scanning phase?
Select an answer first - 14
After compromising a server, an attacker modifies the system log to remove entries related to their login, and then replaces common system binaries with trojanized versions. What is the attacker's primary objective in this step?
Select an answer first - 15
What is the primary objective of the 'gaining access' phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.