Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 9Objective 3

Grey-Box Security Test Tools CT-STE Practice Questions (Page 2)

Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
5concepts

Questions 6–10

  1. 6application · medium

    A grey-box fuzzing campaign on a network service produced hundreds of unique crashes. The tester has source code and can rebuild the service with sanitizers. What is the most effective next step to prioritize which crashes to fix first?

    Select an answer first
  2. 7application · medium

    A small team needs to test a mobile application's backend API. They have the API's source code and want to find vulnerabilities like SQL injection and broken authentication. They have a limited budget and need results quickly. Which tool selection is most appropriate?

    Select an answer first
  3. 8application · medium

    A tester needs to assess a desktop application that uses a proprietary binary protocol for communication. They have the application's source code and want to find memory corruption vulnerabilities. Which tool category is most suitable for this task?

    Select an answer first
  4. 9expert · hard

    A grey-box fuzzer found a crash in a C application. The crash reproduces consistently, but the stack trace points to a library function (e.g., memcpy) with no application frames. The tester has source code and can rebuild with debug symbols. What is the most appropriate action to determine the root cause?

    Select an answer first
  5. 10application · medium

    A tester is assessing a REST API. They have the OpenAPI specification and database schema but not the underlying server implementation. They need to test for authentication bypasses and injection flaws. Which testing approach best matches this situation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.