Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 4Objective 5

Test Oracles Extracted from Standards and Best Practices CT-STE Practice Questions (Page 2)

Part of the Standards and Best Practices domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
6concepts

Questions 6–10

  1. 6expert · hard

    A security tester is evaluating a web application that must comply with both PCI DSS and ISO/IEC 27001. The tester finds that the application uses a single sign-on (SSO) solution that does not log individual user actions. PCI DSS requires logging of all access to cardholder data, while ISO/IEC 27001 requires logging of user activities. The SSO solution is a third-party service that cannot be modified. What should the tester do?

    Select an answer first
  2. 7expert · hard

    A security tester is designing tests for a web application that handles personal data. The tester has two candidate oracles: one from a mandatory data protection regulation and one from a widely accepted industry best practice. The regulation is broad and does not specify technical controls, while the best practice provides detailed technical requirements. The organization must comply with the regulation. What is the most effective approach?

    Select an answer first
  3. 8application · medium

    A security tester is evaluating a web application that processes credit card transactions. The tester needs to verify that the application does not store sensitive authentication data after authorization. Which standard-derived oracle should the tester use to define the expected behavior?

    Select an answer first
  4. 9application · medium

    A security tester is assessing a web application against OWASP ASVS. The tester is at Level 1 and is verifying that the application does not expose sensitive data in URLs. Which ASVS control should the tester use as the oracle?

    Select an answer first
  5. 10application · medium

    A security tester is verifying that a web application uses strong cryptography for storing passwords. Which OWASP ASVS control should the tester use as the oracle?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.