
Certified Tester Security Test Engineer
Domain 2Objective 2
Static and Dynamic Security Testing CT-STE Practice Questions (Page 1)
Part of the Security Test Techniques domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
8concepts
Questions 1–5
- 1
A security team is planning a testing strategy for a new web application. They want to catch coding flaws early in the development cycle and also identify runtime configuration issues before release. The team has limited budget and wants to use a single tool that can address both needs. Which approach is most effective?
Select an answer first - 2
Which practice best integrates static and dynamic security testing into the development process?
Select an answer first - 3
During which phase of the software development lifecycle (SDLC) is dynamic security testing most commonly performed, and what is its primary purpose?
Select an answer first - 4
A security team is integrating security testing into a CI/CD pipeline for a microservices application. The team wants to catch vulnerabilities early, but they also need to ensure that the testing does not introduce significant delays in the pipeline. They have a limited budget and cannot afford to run expensive tools on every build. Which strategy best balances early detection, pipeline performance, and cost?
Select an answer first - 5
How do static and dynamic security testing complement each other in the development process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.