Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 4Objective 1

Standards CT-STE Practice Questions (Page 4)

Part of the Standards and Best Practices domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
7concepts

Questions 16–20

  1. 16application · medium

    A security test engineer is preparing a presentation for management about the importance of security testing standards. The engineer wants to explain the difference between ISO/IEC 27001 and ISO/IEC 25010. Which statement is ACCURATE?

    Select an answer first
  2. 17application · medium

    A security test engineer is planning a network penetration test for a large enterprise. The test must be conducted in a way that minimizes the risk of disrupting production services. The engineer is reviewing NIST SP 800-115 for guidance. Which testing technique, as described in NIST SP 800-115, should the engineer use to minimize disruption?

    Select an answer first
  3. 18application · medium

    A test engineer is explaining to a new team member how different standards support security testing. The engineer wants to clarify that ISO/IEC 25010 provides a framework for defining security quality characteristics, while the OWASP Testing Guide provides practical testing techniques. Which statement correctly describes the relationship between these two standards?

    Select an answer first
  4. 19application · medium

    A security test engineer is using the OWASP Testing Guide to plan a penetration test for a REST API that handles financial transactions. The engineer needs to ensure that the test covers the most relevant security risks for this type of application. According to the OWASP Testing Guide, which testing technique should the engineer prioritize?

    Select an answer first
  5. 20application · medium

    A security test engineer is planning the test approach for a web-based customer portal that handles personal data. The organization has adopted ISO/IEC 25010 as its quality model, and the test manager wants the security testing activities to be traceable to that standard. The engineer must select a testing technique that directly supports the 'Confidentiality' sub-characteristic defined in ISO/IEC 25010. Which activity should the engineer include in the test plan?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.