
Certified Tester Security Test Engineer
Domain 4Objective 1
Standards CT-STE Practice Questions (Page 1)
Part of the Standards and Best Practices domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 1–5
- 1
Why is it important to tailor security testing activities to the context of the system under test?
Select an answer first - 2
Which standard provides a comprehensive framework for managing information security risks through the implementation of an information security management system (ISMS)?
Select an answer first - 3
A retail company processes credit card payments and must comply with PCI DSS. The security test engineer is planning the annual testing activities. The company has a web application that handles cardholder data and a separate internal network that does not. According to PCI DSS requirements, which testing activity is MANDATORY?
Select an answer first - 4
A security test engineer is part of a team that is implementing ISO/IEC 27001. The organization has a mature testing process, but it is not currently aligned with the ISMS. The engineer must integrate security testing into the ISMS. The organization has identified that a critical application has a high risk of data breach due to weak authentication. The ISMS requires a risk treatment plan. Which action BEST integrates the testing process with the ISMS?
Select an answer first - 5
What is the main focus of NIST SP 800-115?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.