
Certified Tester Security Test Engineer
Domain 8Objective 2
Identifying and Analyzing Vulnerabilities CT-STE Practice Questions (Page 1)
Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
6concepts
Questions 1–5
- 1
A tester has confirmed that a cross-site scripting (XSS) vulnerability can be exploited to steal session cookies. Which aspect of vulnerability analysis does this confirmation address?
Select an answer first - 2
What is a key characteristic of an effective vulnerability report?
Select an answer first - 3
You have discovered a vulnerability in a mobile application's API that exposes other users' personal data due to an insecure direct object reference (IDOR). The issue is in a production environment. What is the most critical piece of information to include in the initial report to the client's management team?
Select an answer first - 4
After identifying a SQL injection vulnerability in a search feature, a tester examines the code and determines that the root cause is the direct concatenation of user input into a SQL query. Which activity does this examination represent?
Select an answer first - 5
During a penetration test, you find that a web application is vulnerable to a time-based blind SQL injection. The application is behind a Web Application Firewall (WAF) that blocks requests containing common SQL keywords like 'AND', 'OR', and 'SELECT'. You have confirmed the vulnerability using a payload that avoids these keywords. What is the most important consideration for your final report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.