Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 5Objective 5

Incident Response and Post Incident Analysis CT-STE Practice Questions (Page 3)

Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
6concepts

Questions 11–15

  1. 11foundation · easy

    Which activity is a key part of the lessons learned process to improve incident handling?

    Select an answer first
  2. 12expert · hard

    A security tester is part of a root cause analysis team investigating a ransomware attack. The team has determined that the initial infection occurred through a phishing email. The team is now trying to identify why the phishing email was not blocked by the email gateway. Which approach would be most effective?

    Select an answer first
  3. 13expert · hard

    After a ransomware incident, the incident response team successfully restored systems from backups. The post-incident review reveals that the initial detection was delayed because the security monitoring team did not recognize the early warning signs. The security tester is asked to recommend improvements. Which recommendation would be most effective in preventing a similar delay?

    Select an answer first
  4. 14expert · hard

    A security tester is part of a root cause analysis team investigating a data exfiltration incident. The team has identified that the attacker used a phishing email to obtain credentials. The team is now trying to determine why the phishing email bypassed the email security controls. Which approach would be most effective?

    Select an answer first
  5. 15application · medium

    During a security test, a tester identifies a critical vulnerability in a web application that could allow unauthorized data access. The tester reports it to the incident response team. What is the tester's primary role during the triage phase?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.