
Certified Tester Security Test Engineer
Domain 3Objective 5
System Testing and Acceptance Testing CT-STE Practice Questions (Page 3)
Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
Questions 11–15
- 11
A security test engineer is executing system-level security tests for a new online gaming platform. The platform includes a game server, a matchmaking service, and a user profile database. The engineer needs to verify that the system can prevent a distributed denial-of-service (DDoS) attack on the game server while maintaining the ability for legitimate players to connect. Which of the following is the most appropriate approach for this system-level security test?
Select an answer first - 12
When planning system security tests, what should be defined to ensure the tests are effective?
Select an answer first - 13
What is a key aspect of planning acceptance security tests?
Select an answer first - 14
What does system testing aim to assess regarding the system's security?
Select an answer first - 15
A security test engineer is executing system-level security tests for a new online retail platform. The platform includes a web application, a payment processing service, and a customer database. The engineer needs to verify that the system correctly handles a malicious input that could cause a SQL injection attack. Which of the following is the most appropriate action during system-level security testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.