Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 1Objective 3

Security Audits and Security Testing CT-STE Practice Questions (Page 7)

Part of the Security Paradigms domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
9concepts

Questions 31–35

  1. 31application · medium

    An organization is planning a security audit of its cloud infrastructure. The audit sponsor wants to ensure the audit focuses on the most critical systems and does not waste resources on low-risk areas. What should the audit team define FIRST to achieve this?

    Select an answer first
  2. 32application · medium

    After completing a security audit, the audit team issues a report that identifies several high-risk findings. The report is delivered to management, but no follow-up actions are assigned. What is the MOST likely consequence of this omission?

    Select an answer first
  3. 33application · medium

    A security audit has been completed, and the final report has been issued. The report includes findings and recommendations. What is the MOST important action for the organization to take after the report is issued?

    Select an answer first
  4. 34expert · hard

    A security team is responsible for testing a new application that will be deployed in a highly regulated environment. The team has limited time and must choose between a penetration test and a code review. The primary concern is to identify as many vulnerabilities as possible before deployment. The application is a small, internally developed web application. Which technique is MOST likely to identify a broader range of vulnerabilities?

    Select an answer first
  5. 35expert · hard

    A security team must test a new web application that handles sensitive customer data. The team has a limited budget and must choose between a vulnerability scan and a penetration test. The team wants to identify exploitable vulnerabilities that could lead to a data breach. Which technique is MORE appropriate for this goal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CT-STE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.