
Certified Tester Security Test Engineer
Domain 7Objective 4
Improving Measurability Within an ISMS CT-STE Practice Questions (Page 4)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
Questions 16–20
- 16
A security team needs to report the results of a vulnerability assessment to the IT operations team, which is responsible for patching. What is the most useful way to present the findings?
Select an answer first - 17
A security team has completed a penetration test and needs to report the results to both the technical team and the executive management. What is the most effective reporting strategy?
Select an answer first - 18
A security team is defining objectives for its security testing program. The ISMS manager wants to ensure the objectives are aligned with the organization's goal of reducing cyber risk. Which objective is the most aligned and measurable?
Select an answer first - 19
What is the most important characteristic of a security testing report for stakeholders?
Select an answer first - 20
A security team notices that the 'percentage of vulnerabilities remediated within 30 days' has been decreasing over the last three months. What is the most appropriate first step for the ISMS team?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.