
Certified Tester Security Test Engineer
Domain 7Objective 4
Improving Measurability Within an ISMS CT-STE Practice Questions (Page 1)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
Questions 1–5
- 1
Which action best demonstrates the use of security testing metrics for continuous improvement?
Select an answer first - 2
A security team is evaluating its penetration testing program. They have been tracking the number of vulnerabilities found per test, but the ISMS manager wants a metric that reflects the business impact of the findings. Which metric would best achieve this?
Select an answer first - 3
What is the primary purpose of establishing a baseline for a security testing metric?
Select an answer first - 4
A security team wants to measure the effectiveness of its vulnerability scanning program. They currently track the number of vulnerabilities detected. Which additional metric would best help them assess the program's ability to find real, exploitable issues?
Select an answer first - 5
Which of the following is the best example of a measurable security testing objective aligned with ISMS goals?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.