Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 4Objective 2

Industry Standards for Security Testing CT-STE Practice Questions (Page 2)

Part of the Standards and Best Practices domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)

15questions here
3free pages
4concepts

Questions 6–10

  1. 6application · medium

    A security test engineer is comparing two standards to decide which to use for a web application security assessment. The engineer needs a standard that provides a detailed, verifiable set of security requirements that can be used as a checklist during testing. Which standard best fits this need?

    Select an answer first
  2. 7expert · hard

    A security test engineer is planning a comprehensive security assessment for a large e-commerce platform that handles credit card payments and operates in a regulated industry. The assessment must cover both the web application and the organizational processes. The engineer must select a combination of standards to guide the testing. Which combination of standards is most appropriate for this scenario?

    Select an answer first
  3. 8foundation · easy

    A security test engineer is planning the security testing approach for a large organization that must comply with a standard covering the entire information security management system, including risk assessment, policies, and continuous improvement. Which standard is most applicable to this organizational process context?

    Select an answer first
  4. 9foundation · easy

    A security test engineer is creating a test plan for a web application and needs to include a deliverable that documents the security requirements and test cases derived from the OWASP WSTG. Which deliverable best satisfies this requirement?

    Select an answer first
  5. 10application · medium

    A government contractor must conduct security testing on a web application that will be deployed in a federal environment. The contract requires compliance with a standard that provides a catalog of security controls for federal information systems. Which standard should the testing activities be aligned with?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.