Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 1Objective 2

Information Sensitivity and Security Testing CT-STE Practice Questions (Page 4)

Part of the Security Paradigms domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
3concepts

Questions 16–20

  1. 16expert · hard

    A security test engineer is leading a red team exercise for a large organization. The exercise will involve attempting to access sensitive data through various attack vectors. The organization has a strict rule that the exercise must not cause any service disruption. What is the most important constraint to communicate to the red team?

    Select an answer first
  2. 17expert · hard

    A security test engineer is planning a test that involves social engineering to assess employee awareness. The test will use realistic phishing emails that may trick employees into revealing credentials. The organization has a strict policy against collecting or storing real credentials. What is the best way to conduct this test?

    Select an answer first
  3. 18foundation · easy

    During a security test, a tester encounters a data field labeled 'Restricted' in the system's data dictionary. According to a typical information sensitivity classification scheme, what does this label primarily indicate?

    Select an answer first
  4. 19application · medium

    A security test engineer is working with a client that has a data retention policy requiring that test data be deleted after the test is complete. The engineer has used a cloud-based testing tool that stores data in multiple regions. What should the engineer do to comply with the policy?

    Select an answer first
  5. 20application · medium

    A security test engineer is planning a penetration test for a healthcare organization's patient portal. The test will involve live production data. The organization has classified patient records as 'Confidential' and requires that any test data be anonymized. However, the test team needs realistic data to validate access control flaws. What should the engineer do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.