Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 5Objective 5

Incident Response and Post Incident Analysis CT-STE Practice Questions (Page 7)

Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
6concepts

Questions 31–32

  1. 31expert · hard

    After a data breach, the incident response team identifies that the attacker exploited a vulnerability in a custom web application. The team fixed the specific vulnerability, but the post-incident analysis is ongoing. The security tester is asked to recommend a root cause analysis approach. Which approach would best identify the underlying cause?

    Select an answer first
  2. 32expert · hard

    After a security incident, the post-incident review reveals that the incident response team lacked clear roles and responsibilities, causing delays in containment. The security tester is asked to recommend improvements. Which recommendation would be most effective?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CT-STE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.