
Certified Tester Security Test Engineer
Domain 4Objective 3
Mandatory Application CT-STE Practice Questions (Page 2)
Part of the Standards and Best Practices domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
Questions 6–10
- 6
A financial services company must comply with PCI DSS. The security test team is planning the annual penetration test required by the standard. The compliance officer insists that the test scope must include all systems that store, process, or transmit cardholder data. The team lead wants to ensure the test plan is acceptable to the acquiring bank and the card brands. Which action is most important for the team lead to take?
Select an answer first - 7
A security test engineer is assigned to a project for a government agency that must comply with the Federal Information Security Modernization Act (FISMA). The agency's security testing requirements are based on NIST guidelines. The engineer needs to understand the mandatory application of these standards. Which statement is correct?
Select an answer first - 8
What documentation should be maintained to ensure traceability of security test activities?
Select an answer first - 9
In the reporting phase, what must a security test engineer do to comply with a mandatory standard?
Select an answer first - 10
A security test team is planning a penetration test for a client that must comply with the Payment Card Industry Data Security Standard (PCI DSS). The client's network includes a cardholder data environment (CDE) and a separate corporate network. The team lead must ensure the test plan meets PCI DSS requirements. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.