
Certified Tester Security Test Engineer
Domain 5Objective 5
Incident Response and Post Incident Analysis CT-STE Practice Questions (Page 2)
Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 6–10
- 6
After a security incident, the response team notes that the intrusion was not detected for several days because the monitoring tool was not configured to alert on the specific attack pattern. What is the most appropriate improvement to recommend?
Select an answer first - 7
A security tester discovers a suspicious process running on a production server during a scheduled penetration test. The tester immediately reports it to the incident response team. The team needs to preserve evidence while continuing to monitor the attacker's actions. Which action should the tester take to best support the incident response process?
Select an answer first - 8
Which practice is essential when collecting digital evidence to ensure its admissibility in legal proceedings?
Select an answer first - 9
A security tester is preparing a post-incident report for a distributed denial-of-service (DDoS) attack. The report will be shared with senior management. What is the most important element to include for this audience?
Select an answer first - 10
A security tester is writing a post-incident report after a malware infection. The report will be used to improve the organization's incident response process. What should the report include?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.