Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 9Objective 8

Understand the Usage and Concepts of Dynamic Test Tools CT-STE Practice Questions (Page 6)

Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
8concepts

Questions 26–30

  1. 26foundation · easy

    Which outcome indicates a potential security flaw when using a fuzzing tool?

    Select an answer first
  2. 27application · medium

    A security tester is analyzing a mobile app's API traffic. The app uses HTTPS. To view and modify the traffic, the tester needs to install a custom CA certificate on the testing device. What is the purpose of this step?

    Select an answer first
  3. 28application · medium

    A security tester is analyzing a web application's authentication mechanism. The tester wants to intercept and modify the login request to test for authentication bypass. Which tool is most appropriate for this task?

    Select an answer first
  4. 29application · medium

    A network administrator wants to identify unpatched services on a set of internal servers. The administrator has a list of IP addresses and needs a tool that can scan the network and report missing patches. Which tool is most appropriate?

    Select an answer first
  5. 30foundation · easy

    Which type of vulnerability is most likely to be detected by dynamic analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CT-STE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.