
Certified Tester Security Test Engineer
Domain 5Objective 4
Common Approach of a Hacker CT-STE Practice Questions (Page 5)
Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 21–25
- 21
A penetration tester is performing an external assessment. The tester has gathered information from public sources and now wants to identify open ports and services on the target's firewall. However, the tester is concerned about being detected by the target's intrusion detection system (IDS). Which approach is most likely to minimize the risk of detection while still gathering the needed information?
Select an answer first - 22
A security team is analyzing a series of attacks against their organization. They notice that the attacker spent weeks mapping the network and identifying high-value targets before launching a targeted phishing campaign. Which aspect of the hacker mindset does this behavior best illustrate?
Select an answer first - 23
Which of the following best describes a common motivation for a hacker when targeting a system?
Select an answer first - 24
What is the main goal of covering tracks?
Select an answer first - 25
An attacker exploits a vulnerability in a web server and gains a shell. To ensure they can return even if the vulnerability is patched, the attacker creates a new user account with administrative privileges and schedules a task to run a script that connects back to their server daily. Which phase of the attack lifecycle is the attacker performing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.