
Certified Tester Security Test Engineer
Domain 3Objective 3
Security Test Design at Component Test Level CT-STE Practice Questions (Page 7)
Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
Questions 31–33
- 31
A team is setting up a test environment for a component that depends on a third-party API. The API has rate limits and is not available in the test environment. The team needs to test the component's error handling when the API returns an error. Which approach is most effective?
Select an answer first - 32
What is the purpose of applying threat modeling to a component?
Select an answer first - 33
During threat modeling for a payment-processing component, the team identifies that an attacker could manipulate the transaction amount before it is signed. Which security test design technique would most directly validate whether the component is vulnerable to this threat?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-STE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.