
Certified Tester Security Test Engineer
Domain 3Objective 4
Security Test Design at Component Integration Level CT-STE Practice Questions (Page 1)
Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
8concepts
Questions 1–5
- 1
A company is integrating a customer-facing web portal with an internal CRM system. The integration exposes customer data. The team has limited time for security testing. Which integration security test should be prioritized?
Select an answer first - 2
A company is integrating a new customer relationship management (CRM) system with an existing email system. The integration will allow the CRM to send emails on behalf of users. The team has identified two threats: (1) unauthorized sending of emails via the integration, and (2) email spoofing. The company has limited security testing budget. Which threat should be prioritized?
Select an answer first - 3
What is a primary source for deriving integration-level security test cases?
Select an answer first - 4
Which objective is specific to security testing at the component integration level?
Select an answer first - 5
Which technique is commonly used to test the security of component interfaces by sending unexpected or malformed data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.