
Certified Tester Security Test Engineer
Domain 7Objective 3
Improving Holistic View of an ISMS CT-STE Practice Questions (Page 2)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
Questions 6–10
- 6
How do security testing activities support the objectives of an ISMS?
Select an answer first - 7
In a risk-based approach to security testing within an ISMS, what is the primary factor in deciding which systems to test first?
Select an answer first - 8
A security team is planning tests for the upcoming year. The ISMS risk assessment has identified several risks, but the team has limited resources. They must decide which risks to test first. What is the best way to prioritize?
Select an answer first - 9
How does security testing contribute to the continual improvement process of an ISMS?
Select an answer first - 10
A security test has revealed a critical vulnerability in a core business application. The application owner wants to delay the fix until the next release cycle, but the risk owner believes it should be fixed immediately. How should the security tester facilitate the decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.