Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 3Objective 1

ISTQB Security Test Process CT-STE Practice Questions (Page 1)

Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts

Questions 1–5

  1. 1expert · hard

    A security test team has completed testing and found a vulnerability that could allow an attacker to access sensitive data. The team must report this finding to management, but management is concerned about the cost of fixing the vulnerability. What should the team include in the report to help management make an informed decision?

    Select an answer first
  2. 2foundation · easy

    Which of the following is a key activity in security test planning?

    Select an answer first
  3. 3application · medium

    During a security test, a tester attempts to exploit a SQL injection vulnerability. The application returns a generic error message, but the tester suspects the injection is working because of a time delay. What should the tester do to confirm the vulnerability?

    Select an answer first
  4. 4foundation · easy

    Which of the following is an example of an attack vector that should be considered during security test design?

    Select an answer first
  5. 5foundation · easy

    Which of the following best describes the overall ISTQB security test process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.