
Certified Tester Security Test Engineer
Domain 3Objective 5
System Testing and Acceptance Testing CT-STE Practice Questions (Page 7)
Part of the The Security Test Process domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
Questions 31–35
- 31
A security test engineer is planning acceptance tests for a new cross-border payment system. The stakeholders include the compliance department, which requires that all personal data of EU citizens be stored in the EU, and the operations team, which wants to use a cost-effective cloud provider that has data centers in multiple regions. The engineer must define acceptance criteria that satisfy both stakeholders. Which of the following is the most appropriate acceptance criterion?
Select an answer first - 32
What is a key consideration when evaluating acceptance security test results?
Select an answer first - 33
A security test engineer is executing acceptance tests for a new customer relationship management (CRM) system. The acceptance criteria include that all user access must be logged and that the logs must be tamper-proof. The engineer has executed the tests and the logs are being generated correctly. What is the next step in the acceptance testing process?
Select an answer first - 34
A security test engineer is assigned to test a newly integrated e-commerce platform. The platform consists of a web front-end, a REST API, a payment gateway integration, and a customer database. The engineer needs to verify that the system as a whole correctly enforces access control when a user attempts to view another user's order history. Which type of testing is most appropriate for this scenario?
Select an answer first - 35
A security test engineer is planning acceptance tests for a new financial trading platform. The stakeholders include the compliance department, the risk management team, and the IT operations team. The engineer needs to define acceptance criteria and involve stakeholders in the test design. Which of the following is the most effective approach for planning these acceptance security tests?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-STE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.