
Certified Tester Security Test Engineer
Domain 8Objective 3
Hide Vulnerability CT-STE Practice Questions (Page 1)
Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
Questions 1–5
- 1
What is the primary purpose of assigning a severity rating to a vulnerability?
Select an answer first - 2
A tester finds a vulnerability that allows an attacker to read the contents of a database, but only if they are already authenticated as a low-privileged user. The database contains non-sensitive operational data. How should the tester rate the severity of this finding?
Select an answer first - 3
A researcher discovers a vulnerability in a small, open-source project maintained by a single developer. The researcher has tried to contact the developer via email and the project's issue tracker but has received no response for several weeks. The vulnerability is serious and could be exploited. What is the most appropriate next step?
Select an answer first - 4
Which of the following is the most appropriate channel for reporting a vulnerability discovered in a commercial software product?
Select an answer first - 5
A security researcher is part of a team that discovers a vulnerability in a widely used software library. The team is planning to disclose the vulnerability to the vendor. However, a team member wants to publish a blog post about the discovery to gain recognition. What is the most important consideration for the team to discuss?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.