
Certified Tester Security Test Engineer
Domain 9Objective 4
Static Security Test Tools CT-STE Practice Questions (Page 1)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
6concepts
Questions 1–5
- 1
A development team wants to identify known vulnerabilities in the third-party libraries their application uses. Which type of tool is most appropriate for this task?
Select an answer first - 2
Which of the following best describes the difference between a SAST tool and a linter?
Select an answer first - 3
A team is building a web application in JavaScript and wants to catch common security issues such as cross-site scripting (XSS) and insecure use of eval(). They also want to enforce consistent code style. Which tool category is best suited for this task?
Select an answer first - 4
A security team wants to integrate a SAST tool into their developer workflow. They want to provide feedback to developers as early as possible, ideally before the code is committed. What is the best way to achieve this?
Select an answer first - 5
How might an attacker attempt to evade detection by a static analysis tool?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.