
Certified Tester Security Test Engineer
Domain 9Objective 3
Grey-Box Security Test Tools CT-STE Practice Questions (Page 4)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
5concepts
Questions 16–20
- 16
When operating a grey-box fuzzer, what is a typical configuration step to improve test coverage?
Select an answer first - 17
A grey-box fuzzer is testing a file parser. The fuzzer has found a crash, but the crash is not reproducible when the same input is run again. The tester has the source code and can rebuild. What is the most likely cause of the non-reproducible crash?
Select an answer first - 18
When prioritizing vulnerabilities found by grey-box tools, which factor is most important to consider?
Select an answer first - 19
In grey-box security testing, the tester typically has:
Select an answer first - 20
A security team must choose a grey-box tool to test a Java microservices application that uses Kafka for messaging and exposes REST endpoints. The team has the source code and CI/CD pipeline. They need to find both concurrency bugs and injection flaws, and they have a limited budget for commercial tools. Which tool selection best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.