
Certified Tester Security Test Engineer
Domain 9Objective 7
Understand the Usage and Concepts of Static Security Test Tools CT-STE Practice Questions (Page 2)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 12 practice questions to prepare you well beyond it. (estimate)
12questions here
3free pages
7concepts
Questions 6–10
- 6
What is the primary purpose of static security test tools in the software development lifecycle?
Select an answer first - 7
A static analysis tool is configured to detect buffer overflows in a C++ codebase. The tool uses a technique that examines the sequence of operations in each function to identify potential overflows. Which technique is this?
Select an answer first - 8
A startup is building a new microservices-based application and wants to integrate security testing early in the development process. They have a small team and limited budget. Which approach would be most effective?
Select an answer first - 9
A security analyst is reviewing a static analysis report for a Java application. The tool flagged a potential SQL injection vulnerability where user input flows from an HTTP request parameter into a SQL query without sanitization. Which static analysis technique is most likely responsible for this finding?
Select an answer first - 10
A security analyst is reviewing a static analysis report and notices that the tool did not flag a known vulnerability in a third-party library that is used in the project. The analyst knows the library has a known CVE. What is the most likely reason for this gap?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.