
Certified Tester Security Test Engineer
Domain 7Objective 2
Input for an Information Security Management System (ISMS) CT-STE Practice Questions (Page 3)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
Questions 11–15
- 11
Which of the following is a way security testing supports incident management?
Select an answer first - 12
An organization has implemented a new web application firewall (WAF) as a security control. The ISMS manager wants to verify that the control is working as intended. Which security testing activity provides the most direct evidence of control effectiveness?
Select an answer first - 13
An organization has implemented multi-factor authentication (MFA) for remote access. To evaluate the effectiveness of this control, which security testing approach is most appropriate?
Select an answer first - 14
A security test reveals that a recurring misconfiguration in database servers allows unauthorized access. The root cause is a lack of standardized configuration templates. As part of the ISMS continuous improvement cycle, what should the organization do?
Select an answer first - 15
How can security testing inputs support incident management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.