
Certified Tester Security Test Engineer
Domain 7Objective 2
Input for an Information Security Management System (ISMS) CT-STE Practice Questions (Page 4)
Part of the Security Testing as Part of an Information Security Management System domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
Questions 16–20
- 16
After a security test, the test engineer prepares a report with technical details of vulnerabilities. The ISMS manager needs to present the results to the board of directors. What is the most appropriate way to communicate the findings?
Select an answer first - 17
How do security testing inputs feed into the continuous improvement cycle of an ISMS?
Select an answer first - 18
Which of the following is an example of an input that security testing provides to an ISMS?
Select an answer first - 19
An organization has implemented a security control that is expensive to operate. The ISMS manager wants to evaluate whether the control is worth the cost. Which combination of security testing inputs would provide the most useful information for this decision?
Select an answer first - 20
In the context of ISMS risk management, what role do security testing results play in risk evaluation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.