
Certified Tester Security Test Engineer
Domain 7Objective 2
Input for an Information Security Management System (ISMS) CT-STE Practice Questions (Page 1)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
Questions 1–5
- 1
What type of evidence does security testing provide regarding control effectiveness?
Select an answer first - 2
In what way do security testing results support internal and external audits?
Select an answer first - 3
How do security testing results inform the risk identification step of risk management within an ISMS?
Select an answer first - 4
A security test identifies a vulnerability that was previously reported and supposedly fixed. The ISMS manager is concerned that the continuous improvement process is not working. What is the most likely reason for the recurrence?
Select an answer first - 5
An external auditor requests evidence that the organization's access control policy is being enforced. Which security testing artifact would best support this compliance claim?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.