
Certified Tester Security Test Engineer
Domain 9Objective 3
Grey-Box Security Test Tools CT-STE Practice Questions (Page 6)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
5concepts
Questions 26–29
- 26
A tester is new to a project and has been given the database schema and API documentation for a web application, but not the source code. They are asked to perform a security assessment focusing on business logic flaws. Which approach is most aligned with grey-box testing principles?
Select an answer first - 27
A tester is assessing a web application and has been given the source code of the authentication module but not the rest of the application. They want to test for authorization flaws. Which approach best leverages this partial knowledge?
Select an answer first - 28
A tester is assessing a web application and has the source code. They want to find both client-side and server-side vulnerabilities. Which combination of grey-box tool categories is most effective?
Select an answer first - 29
A team needs to test a Node.js application that uses a NoSQL database. They have the source code and want to find injection flaws and insecure deserialization. Which tool selection is most appropriate?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-STE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.