
Certified Tester Security Test Engineer
Domain 5Objective 2
The Impact of Regulations on Security Regulations CT-STE Practice Questions (Page 4)
Part of the Adjusting To the Organizational Context domain, which makes up ~10% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
7concepts
Questions 16–20
- 16
A security test team is developing a test strategy for a new payment processing system. The system must comply with PCI DSS and the company's internal security policies. The team has limited resources and must choose between testing all PCI DSS requirements or focusing on the highest-risk areas. Which approach is most appropriate?
Select an answer first - 17
A security test team is developing a risk-based test strategy for a new banking application. The application will handle sensitive financial data and must comply with industry regulations. The team has identified that the highest risk is unauthorized access to customer accounts. Which test activity should be prioritized in the strategy?
Select an answer first - 18
When a regulation changes, what is the first step a security test team should take to maintain compliance?
Select an answer first - 19
Which regulation is specifically applicable to organizations that process payment card data and requires security testing of cardholder data environments?
Select an answer first - 20
What type of documentation is typically required by regulations to demonstrate that security testing has been performed and controls are effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.