
Certified Tester Security Test Engineer
Domain 8Objective 1
Security Test Reporting CT-STE Practice Questions (Page 2)
Part of the Reporting Test Results domain, which makes up ~8% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
Questions 6–10
- 6
A security test found a high-risk vulnerability in a legacy system that cannot be patched immediately. What should the report recommend?
Select an answer first - 7
A security test identified a critical SQL injection vulnerability in a customer-facing application. The report must be shared with two audiences: the development team and the product manager. How should the findings be presented to each audience?
Select an answer first - 8
A security test report contains findings with different risk levels. The report is intended for the IT operations team that will implement fixes. How should the findings be prioritized in the report?
Select an answer first - 9
A security testing team wants to report on the effectiveness of their testing process to management. Which KPI would best demonstrate the value of the security testing program?
Select an answer first - 10
A security test report is being prepared for a client that requires compliance with a specific regulatory standard. The client wants to know if the application meets the standard's security requirements. What should the report include?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.