
Certified Tester Security Test Engineer
Domain 9Objective 1
White-Box Security Test Tools CT-STE Practice Questions (Page 1)
Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
6concepts
Questions 1–5
- 1
A security team is integrating SAST into a CI/CD pipeline that uses a build system that compiles code incrementally. The team notices that SAST scans are slow and are delaying the pipeline. Which approach best addresses the performance issue while maintaining security coverage?
Select an answer first - 2
A SAST tool is analyzing a C# application that uses an ORM (Entity Framework) to query a database. The tool does not report any SQL injection vulnerabilities. Which is the most likely reason for this?
Select an answer first - 3
A development team uses a monorepo containing multiple microservices written in different languages. They want to integrate SAST into their CI/CD pipeline. Which approach is most effective for managing this complexity?
Select an answer first - 4
A company develops a mobile banking application in Kotlin and a backend service in Go. The security team wants to select a single SAST tool for both codebases. Which factor is most important to evaluate first?
Select an answer first - 5
Which of the following is a typical output of a SAST tool?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.