
Certified Tester Security Test Engineer
Domain 3Objective 3
Security Test Design at Component Test Level CT-STE Practice Questions (Page 2)
Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
Questions 6–10
- 6
What should be included in the documentation of component-level security test results?
Select an answer first - 7
A security test lead wants to ensure that every identified security risk for a component has at least one corresponding test case. Which artifact should the team maintain to demonstrate this?
Select an answer first - 8
A team is testing a component that performs cryptographic operations. They need to verify that the component correctly rejects tampered ciphertext. Which tool or test double is most appropriate for this task?
Select an answer first - 9
What is the main advantage of using security-focused white-box testing at the component level?
Select an answer first - 10
A team is testing a component that processes user-supplied JSON data. Threat modeling identified a risk of prototype pollution. The team has limited time and must choose one security test technique. Which technique is most effective for detecting this specific vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.