Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 5Objective 1

The Impact of Organizational Structures in the Context of Security Testing CT-STE Practice Questions (Page 1)

Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
4concepts

Questions 1–5

  1. 1application · medium

    A small company with a flat structure has a single security tester who reports directly to the CEO. The CEO wants to launch a new product quickly and asks the tester to skip the full security test to meet the deadline. The tester believes the product has significant security risks. What is the MOST appropriate action for the tester?

    Select an answer first
  2. 2application · medium

    A software company uses a matrix structure. A security tester is assigned to a product team and also reports to the security manager. The security manager asks the tester to spend 50% of their time on a new security initiative, but the product manager insists the tester is needed full-time for the upcoming release. What is the MOST appropriate way for the tester to handle this conflict?

    Select an answer first
  3. 3foundation · easy

    An organization has a functional structure with a centralized security team. Which security testing approach is most aligned with this structure?

    Select an answer first
  4. 4application · medium

    A startup with a flat, project-based structure has no dedicated security team. Developers are responsible for security testing their own code. The company is about to launch a public API and wants to ensure it is secure without hiring new staff. Which approach BEST fits this organizational context?

    Select an answer first
  5. 5application · medium

    In a functional organization, the security testing team reports to the IT operations manager. During a penetration test, the team finds a critical vulnerability in a legacy application owned by the finance department. The finance department refuses to acknowledge the risk because they were not involved in the test planning. What is the PRIMARY reason this conflict occurred?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.