
Certified Tester Security Test Engineer
Domain 2Objective 7
Testing Protective Technologies CT-STE Practice Questions (Page 3)
Part of the Security Test Techniques domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
10concepts
Questions 11–15
- 11
What is a false positive in the context of an intrusion detection system (IDS)?
Select an answer first - 12
During a security assessment, the tester needs to verify that security logs are sufficient for incident detection. Which log source is most critical to include?
Select an answer first - 13
What is the basic function of encryption as a protective technology?
Select an answer first - 14
A security tester is reviewing the patch management process for a network of 500 workstations. The tester finds that patches are deployed manually by IT staff and that some machines have not been updated in over six months. What is the most appropriate recommendation?
Select an answer first - 15
A tester is validating authentication controls on a web application. The tester finds that the application allows an unlimited number of login attempts without any lockout or rate limiting. What is the most appropriate recommendation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.