Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 8Objective 2

Identifying and Analyzing Vulnerabilities CT-STE Practice Questions (Page 4)

Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
6concepts

Questions 16–20

  1. 16foundation · easy

    During a security test, a tester observes that the application returns detailed stack traces in HTTP error responses. Which activity does this observation directly support?

    Select an answer first
  2. 17expert · hard

    You are testing a web application and have discovered a critical vulnerability. You have captured the proof-of-concept (PoC) request and response in your proxy tool. However, the response contains a session token for the test account you used. What is the most appropriate way to handle this evidence for the final report?

    Select an answer first
  3. 18expert · hard

    Your security assessment of a healthcare application has identified two critical findings. Finding A is a SQL injection in the patient portal that could expose Protected Health Information (PHI). Finding B is a remote code execution (RCE) vulnerability in a legacy internal reporting tool that is not directly accessible from the internet. The client has limited resources and can only fix one vulnerability this quarter. Which vulnerability should you recommend they fix first?

    Select an answer first
  4. 19foundation · easy

    A tester has identified two vulnerabilities: one with high likelihood and low impact, and another with low likelihood and high impact. Which activity would help determine which vulnerability to address first?

    Select an answer first
  5. 20application · medium

    You are documenting a complex business logic flaw in an e-commerce application that allows a user to apply a discount code multiple times. You have a series of screenshots showing the steps. What is the most effective way to present this evidence in the vulnerability report?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CT-STE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.