
Certified Tester Security Test Engineer
Domain 7Objective 4
Improving Measurability Within an ISMS CT-STE Practice Questions (Page 2)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
Questions 6–10
- 6
Which metric is most appropriate for measuring the coverage of security testing?
Select an answer first - 7
A security team is selecting metrics for its ISMS. They want to measure the effectiveness of their security testing program. Which combination of metrics would provide the most comprehensive view?
Select an answer first - 8
How can security testing metrics be used to drive continuous improvement within an ISMS?
Select an answer first - 9
A security team has been running monthly vulnerability scans for six months. They now want to establish a baseline for the metric 'percentage of critical vulnerabilities remediated within 30 days'. What is the most appropriate way to establish this baseline?
Select an answer first - 10
After a year of tracking security testing metrics, a company notices that the 'percentage of vulnerabilities found by internal testing versus external penetration tests' has shifted from 60/40 to 30/70. What is the most appropriate action for the ISMS team?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.