
Certified Tester Security Test Engineer
Domain 1Objective 5
Zero Trust Concept in Security Testing CT-STE Practice Questions (Page 3)
Part of the Security Paradigms domain, which makes up ~12% of our current practice bank. ISTQB does not publish an official question count, but from its 75-minute exam (~30–50 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
6concepts
Questions 11–15
- 11
What is the primary purpose of testing continuous authentication in a Zero Trust environment?
Select an answer first - 12
During threat modeling for a Zero Trust architecture, the team is considering the risk of an insider threat. The architecture includes data loss prevention (DLP) and user behavior analytics (UBA). Which threat modeling approach best incorporates Zero Trust assumptions?
Select an answer first - 13
A company is adopting Zero Trust and wants to update its security testing strategy. The CISO emphasizes that the strategy must reflect the principle of least privilege. Which testing approach best aligns with this principle?
Select an answer first - 14
A company is implementing Zero Trust and has deployed a new identity provider (IdP) that integrates with all applications. As a security test engineer, you are asked to test the identity component. Which test is most relevant?
Select an answer first - 15
A Zero Trust architecture includes a data security component that encrypts data at rest and in transit. As a security test engineer, you are asked to test the data security controls. Which test is most relevant?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-STE” is a trademark of its owner, used for identification only.