Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 5Objective 1

The Impact of Organizational Structures in the Context of Security Testing CT-STE Practice Questions (Page 3)

Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
4concepts

Questions 11–15

  1. 11application · medium

    A project-based organization creates a temporary team for a 6-month government contract. The team includes developers, a security tester, and a project manager, all reporting directly to the project manager. The security tester wants to report a critical finding to the organization's central security office, but the project manager insists on reporting only to the client. What is the MOST significant risk of following the project manager's directive?

    Select an answer first
  2. 12application · medium

    A non-profit organization has a flat structure with a small IT team. They are planning to conduct a security assessment of their donor database. There is no dedicated security tester, and the IT team has limited security expertise. What is the MOST appropriate approach for the organization?

    Select an answer first
  3. 13expert · hard

    A multinational corporation with a matrix structure is undergoing a merger. The security testing team is now split across two reporting lines: one from the legacy company and one from the new partner. The two lines have conflicting testing methodologies and reporting formats. What is the MOST effective way to integrate the two teams?

    Select an answer first
  4. 14expert · hard

    A large enterprise with a matrix structure is adopting a DevOps culture. Security testers are embedded in product teams, but they still report to a central security officer. The central security officer wants to enforce a standardized security testing toolchain across all teams, while individual product teams want to use their own tools to speed up delivery. What is the BEST way to resolve this tension while maintaining effective security testing?

    Select an answer first
  5. 15foundation · easy

    In which organizational structure are security testers typically assigned to a dedicated project team for the duration of the project and then reassigned to a new project?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.