Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISTQB logo

Certified Tester Security Test Engineer

Domain 9Objective 1

White-Box Security Test Tools CT-STE Practice Questions (Page 2)

Part of the Security Test Tools domain, which makes up ~15% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
6concepts

Questions 6–10

  1. 6expert · hard

    A SAST tool is analyzing a web application and reports a stored XSS vulnerability. The data flow is: user input → database → HTML output. The tool also reports that the input is sanitized before being stored in the database. What is the most accurate interpretation of these findings?

    Select an answer first
  2. 7foundation · easy

    Which of the following is a category of white-box security test tools?

    Select an answer first
  3. 8foundation · easy

    What is a common way to integrate SAST tools into a CI/CD pipeline?

    Select an answer first
  4. 9foundation · easy

    Which organizational factor should influence the selection of a white-box security test tool?

    Select an answer first
  5. 10application · medium

    A startup with a small team and a limited budget wants to add SAST to their CI pipeline. They use GitHub and GitHub Actions. Which approach is most cost-effective and practical for their context?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.