
Certified Tester Security Test Engineer
Domain 7Objective 3
Improving Holistic View of an ISMS CT-STE Practice Questions (Page 3)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
Questions 11–15
- 11
During a security test, a tester discovers that a control documented in the ISMS is not actually implemented. What should the tester do to support the ISMS process?
Select an answer first - 12
A company is building a holistic security testing strategy. They have a mix of on-premises and cloud systems, and a remote workforce. What should the strategy include to be truly holistic?
Select an answer first - 13
During an ISMS risk assessment, a new critical vulnerability is discovered in a customer-facing application. According to ISMS processes, what is the most appropriate next step?
Select an answer first - 14
An organization's ISMS risk assessment has identified two high-risk areas: a public-facing web application and an internal HR system. The web application is exposed to the internet, while the HR system contains sensitive employee data. The testing budget allows for only one full-scale test this quarter. How should the security team decide which area to test?
Select an answer first - 15
After a penetration test, the security team needs to report findings to different stakeholders. The board of directors wants a high-level overview, while IT operations needs technical details. How should the security team communicate the results?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.