Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 8Objective 3

Hide Vulnerability CT-STE Practice Questions (Page 5)

Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
6concepts

Questions 21–25

  1. 21application · medium

    A penetration test reveals a SQL injection vulnerability in a legacy application that is scheduled to be decommissioned in 18 months. The application is business-critical and cannot be taken offline for a major refactor. What is the most practical remediation guidance to provide in the report?

    Select an answer first
  2. 22application · medium

    A tester is writing a report and needs to explain the severity of a vulnerability to a client. The vulnerability allows an attacker to cause a denial of service (DoS) on a public-facing web server by sending a single, specially crafted request. How should the tester classify this vulnerability?

    Select an answer first
  3. 23expert · hard

    A security team discovers a critical vulnerability in a custom-built application. The development team is overwhelmed with feature requests and does not have the capacity to fix the vulnerability for at least six months. The application is internet-facing and processes sensitive customer data. What is the most appropriate immediate action for the security team to recommend?

    Select an answer first
  4. 24foundation · easy

    Why is it important to tailor the communication of vulnerability findings to the audience?

    Select an answer first
  5. 25application · medium

    A security researcher discovers a critical remote code execution vulnerability in a widely used open-source web server. The researcher has confirmed the flaw in a lab environment and has a working proof-of-concept. The vendor has a public bug tracker but no dedicated security contact. What is the most appropriate first step for the researcher?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.