
Certified Tester Security Test Engineer
Domain 5Objective 3
Common Attack Scenarios CT-STE Practice Questions (Page 6)
Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
Questions 26–27
- 26
What is the primary purpose of studying common attack scenarios in the context of security testing?
Select an answer first - 27
A security tester is analyzing a past breach where attackers exploited a SQL injection vulnerability in a public-facing web form. The attackers then used the database access to extract hashed passwords and later cracked them to gain access to internal systems. Which mitigation would have been MOST effective in preventing the attackers from moving from the web form to the internal systems?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-STE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.