
Certified Tester Security Test Engineer
Domain 5Objective 5
Incident Response and Post Incident Analysis CT-STE Practice Questions (Page 1)
Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 1–5
- 1
A post-incident review of a data breach reveals that the security testing team did not include the breached application in its test scope because of a miscommunication with the development team. The security tester is asked to recommend improvements. Which recommendation would be most effective?
Select an answer first - 2
A security tester is involved in the eradication phase of an incident response. The team has contained the incident and is now removing the attacker's presence from the system. What is the tester's role in this phase?
Select an answer first - 3
What is the primary purpose of creating a forensic image (bit-for-bit copy) of a storage device during incident response?
Select an answer first - 4
How can a security test finding, such as an unexpected open port on a production server, contribute to incident detection?
Select an answer first - 5
A security tester is collecting evidence from a compromised web server. The tester wants to preserve the evidence in a way that is acceptable for legal proceedings. What should the tester do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.