
Certified Tester Security Test Engineer
Domain 8Objective 2
Identifying and Analyzing Vulnerabilities CT-STE Practice Questions (Page 2)
Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
6concepts
Questions 6–10
- 6
In risk assessment, what two factors are primarily considered to determine the risk of a vulnerability?
Select an answer first - 7
Which element should be included in a vulnerability report to help stakeholders understand the potential business consequences?
Select an answer first - 8
While analyzing the results of an automated vulnerability scan of a network, you notice a 'High' severity finding for 'SSL Certificate Expired' on an internal application server. The server is only accessible from the internal corporate network and is used by a small team for a non-critical project. What is the most appropriate next step?
Select an answer first - 9
During a security test, a tester captures a screenshot of an error message that reveals sensitive information. What is the primary purpose of this action?
Select an answer first - 10
You have identified a vulnerability in a web application where user input is used to construct a file path for a download feature. By manipulating the input, an attacker can download arbitrary files from the server (e.g., /etc/passwd). You need to classify this vulnerability for the report. Which classification is the most accurate and useful for the development team?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.