
Certified Tester Security Test Engineer
Domain 2Objective 5
Testing Identification, Authentication and Authorization CT-STE Practice Questions (Page 4)
Part of the Security Test Techniques domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
7concepts
Questions 16–20
- 16
Which test would detect a horizontal privilege escalation vulnerability?
Select an answer first - 17
What is the primary goal of authorization testing?
Select an answer first - 18
Why is it important to test the interaction between authentication and authorization?
Select an answer first - 19
A security tester is evaluating a web application that uses a password-based authentication system. The tester notices that the application stores passwords using a salted hash. However, the tester also discovers that the application does not enforce a minimum password length or complexity. Which of the following is the MOST significant risk associated with this finding?
Select an answer first - 20
A tester is assessing a web application that uses OAuth 2.0 for authorization. The application redirects the user to an authorization server, which then redirects back to the application with an authorization code. The tester notices that the application accepts the authorization code from any redirect URI, not just the one registered. Which of the following attacks is the tester MOST likely able to perform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.