
Certified Tester Security Test Engineer
Domain 2Objective 5
Testing Identification, Authentication and Authorization CT-STE Practice Questions (Page 5)
Part of the Security Test Techniques domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
7concepts
Questions 21–24
- 21
A security tester is evaluating a web application that uses a session cookie for authentication. The tester notices that the session cookie is set with the 'Secure' flag but not the 'HttpOnly' flag. The tester also discovers a stored XSS vulnerability in the application. Which of the following is the MOST significant additional risk introduced by the missing 'HttpOnly' flag?
Select an answer first - 22
A security tester is assessing a web application that allows users to register with an email address. The application sends a verification email with a link that contains a token. The tester notices that the token is a sequential number (e.g., 12345, 12346). Which of the following is the MOST significant risk associated with this design?
Select an answer first - 23
A tester is reviewing a microservices architecture where each service uses its own JWT for authorization. The tester discovers that the JWT signing key is shared across all services. An attacker compromises one service and extracts the signing key. Which of the following is the MOST significant security impact?
Select an answer first - 24
A tester is evaluating a mobile banking application that uses biometric authentication (fingerprint) to authorize transactions. The tester discovers that the application stores a cryptographic key in the device's secure enclave, and the fingerprint is used to unlock the key. However, the tester also finds that the application has a 'fallback' mechanism that allows the user to enter a 4-digit PIN if the fingerprint fails. The tester attempts to brute-force the PIN by trying all 10,000 combinations. The application does not have any rate limiting or lockout mechanism. Which of the following is the MOST significant security weakness in this design?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CT-STE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.