
Certified Tester Security Test Engineer
Domain 9Objective 3
Grey-Box Security Test Tools CT-STE Practice Questions (Page 5)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
5concepts
Questions 21–25
- 21
A security team needs to select a grey-box tool for a web application built with Python and React. Which factor is most important to consider first?
Select an answer first - 22
A grey-box test of a web application found a SQL injection vulnerability in a search feature. The tester has the source code and can see the vulnerable query. What is the most appropriate way to report this finding to the development team?
Select an answer first - 23
When selecting a grey-box security test tool, which of the following is a key resource constraint to consider?
Select an answer first - 24
Which statement best describes how grey-box testing combines black-box and white-box approaches?
Select an answer first - 25
A grey-box fuzzer is testing a web application's file upload feature. The fuzzer is configured with a dictionary of common file names and payloads. However, the fuzzer is not finding any vulnerabilities. The tester has the source code and knows the upload validation logic. What is the most effective way to improve the fuzzer's effectiveness?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.