Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 3Objective 4

Security Test Design at Component Integration Level CT-STE Practice Questions (Page 3)

Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
8concepts

Questions 11–15

  1. 11application · medium

    A team is integrating a new file upload service with an existing web application. The service accepts files from users and stores them in a cloud storage bucket. The team wants to test the security of the integration. Which security test design technique is most appropriate to test the file upload service's handling of malicious files?

    Select an answer first
  2. 12application · medium

    Two microservices communicate via a message queue. The sending service serializes objects using Java serialization. The receiving service deserializes them. As a security test engineer, what is the most important interface security concern to address in your test design?

    Select an answer first
  3. 13foundation · easy

    What is the purpose of traceability between integration-level security test cases and security requirements?

    Select an answer first
  4. 14foundation · easy

    What is the main purpose of threat modeling at the component integration level?

    Select an answer first
  5. 15foundation · easy

    What is the primary focus of interface security analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.