Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 3Objective 4

Security Test Design at Component Integration Level CT-STE Practice Questions (Page 2)

Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
8concepts

Questions 6–10

  1. 6application · medium

    Two systems exchange data using a proprietary binary protocol over a TCP connection. The protocol has no built-in authentication or integrity checks. What is the most important security test to design for this interface?

    Select an answer first
  2. 7expert · hard

    A security test engineer is performing threat modeling for a new integration between a mobile app and a backend server. The mobile app uses a third-party SDK for analytics. The threat model identifies that the SDK could be compromised and send malicious data to the backend. What is the most effective mitigation to test?

    Select an answer first
  3. 8expert · hard

    Two components in a system communicate via a message queue. The sending component is known to occasionally send malformed messages due to a bug. The receiving component crashes when it receives a malformed message. What is the most appropriate security test to design for this interaction?

    Select an answer first
  4. 9application · medium

    A team is integrating a new authentication service with an existing application. The integration uses a REST API. The team wants to test the robustness of the interface against unexpected input. Which security test design technique is most appropriate for this scenario?

    Select an answer first
  5. 10application · medium

    A team is integrating a new reporting module into an existing application. The module will access sensitive financial data. The team needs to define the scope of security testing for this integration. What is the most important factor to consider when defining the scope?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.