
Certified Tester Security Test Engineer
Domain 4Objective 1
Standards CT-STE Practice Questions (Page 3)
Part of the Standards and Best Practices domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 11–15
- 11
What is the primary purpose of PCI DSS in relation to security testing?
Select an answer first - 12
Which standard requires organizations that handle payment card data to conduct regular vulnerability scans and penetration tests?
Select an answer first - 13
A security test engineer is testing a new online banking application. The application allows users to transfer money between accounts. The engineer has already tested for confidentiality (e.g., encryption of data in transit) and integrity (e.g., preventing tampering with transaction amounts). According to ISO/IEC 25010, which additional security sub-characteristic should the engineer test to ensure the application is secure?
Select an answer first - 14
When planning security testing activities, what is the first step in mapping them to relevant standards?
Select an answer first - 15
Which ISO/IEC 25010 security sub-characteristic is most directly related to ensuring that data has not been altered or destroyed in an unauthorized manner?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.