
Certified Tester Security Test Engineer
Domain 5Objective 4
Common Approach of a Hacker CT-STE Practice Questions (Page 4)
Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 16–20
- 16
An attacker has gained access to a server and wants to maintain persistence. The attacker considers the following options: creating a new user account, installing a rootkit, or modifying a scheduled task. The attacker knows that the organization uses host-based intrusion detection (HIDS) and regularly reviews user accounts. Which option is most likely to avoid detection while ensuring persistence?
Select an answer first - 17
A penetration tester discovers that a web application is vulnerable to SQL injection. The tester uses this vulnerability to bypass the login form and access the admin panel. Which phase of the attack lifecycle does this action represent?
Select an answer first - 18
What is the main purpose of the reconnaissance phase in a hacker's attack?
Select an answer first - 19
Which of the following is an example of passive reconnaissance?
Select an answer first - 20
Which of the following is a common method for maintaining access to a compromised system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.