
Certified Tester Security Test Engineer
Domain 4Objective 1
Standards CT-STE Practice Questions (Page 5)
Part of the Standards and Best Practices domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
Questions 21–25
- 21
How does ISO/IEC 27001 influence security testing processes within an organization?
Select an answer first - 22
Which NIST Special Publication provides technical guidance for conducting security testing and assessment?
Select an answer first - 23
A security test engineer is working for a company that processes credit card payments. The company is preparing for a PCI DSS audit. The engineer is reviewing the testing requirements. Which activity is a specific requirement of PCI DSS that is NOT typically required by other standards like ISO/IEC 27001?
Select an answer first - 24
A security test engineer is using the OWASP Testing Guide to test a web application that allows users to upload files. The engineer wants to ensure that the file upload functionality is secure. According to the OWASP Testing Guide, which testing technique is specifically relevant to this functionality?
Select an answer first - 25
Which component of the OWASP Testing Guide provides a structured approach to testing a specific security control or vulnerability class?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.