Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 4Objective 2

Industry Standards for Security Testing CT-STE Practice Questions (Page 1)

Part of the Standards and Best Practices domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)

15questions here
3free pages
4concepts

Questions 1–5

  1. 1application · medium

    A security test engineer is evaluating two standards for a project. The engineer needs a standard that is a technical guide for conducting security testing, providing methodologies and techniques, rather than a set of requirements or a management framework. Which standard should the engineer select?

    Select an answer first
  2. 2foundation · easy

    An organization is developing a mobile banking app and needs to select a security testing standard that specifically addresses mobile application security. Which standard is most appropriate for this context?

    Select an answer first
  3. 3application · medium

    A security test engineer is documenting the testing approach for a web application. The documentation must include a mapping of testing activities to a standard that provides a comprehensive set of security requirements organized by verification level. Which standard should the engineer reference?

    Select an answer first
  4. 4application · medium

    A security test engineer must choose between two standards for a project: one that provides a high-level framework for managing security risks across the organization, and another that provides detailed technical requirements for testing a specific application. Which pair of standards correctly matches these descriptions?

    Select an answer first
  5. 5foundation · easy

    Which industry standard is primarily focused on providing a framework for managing information security risks through a set of policies and controls, rather than prescribing specific testing techniques?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.