
Certified Tester Security Test Engineer
Domain 3Objective 4
Security Test Design at Component Integration Level CT-STE Practice Questions (Page 3)
Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
8concepts
Questions 11–15
- 11
A team is integrating a new file upload service with an existing web application. The service accepts files from users and stores them in a cloud storage bucket. The team wants to test the security of the integration. Which security test design technique is most appropriate to test the file upload service's handling of malicious files?
Select an answer first - 12
Two microservices communicate via a message queue. The sending service serializes objects using Java serialization. The receiving service deserializes them. As a security test engineer, what is the most important interface security concern to address in your test design?
Select an answer first - 13
What is the purpose of traceability between integration-level security test cases and security requirements?
Select an answer first - 14
What is the main purpose of threat modeling at the component integration level?
Select an answer first - 15
What is the primary focus of interface security analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.