Skip to content

Certified Tester Security Tester

Here you have the best ISTQB CT-SEC practice exam questions

  • Preview the first 5 of 45 questions for free
  • These questions were last updated on May 14, 2026
  • This site is not affiliated with or endorsed by ISTQB.
Question 1 of 45

Which ONE of the following security vulnerabilities can be identified through structural testing during component testing?
Answer

Suggested Answer

The suggested answer is B.

Question 2 of 45

Scenario:
At “Happy Wrench Plumbing”, an administrator (admin) manages clients and other users and is able to edit their personal details in the application by accessing the URL: http://www.abcxyz.com/editusers.
It is necessary to test if non-admin users can perform this above-mentioned functionality.
Question:
Which ONE of the following options CORRECTLY corresponds to the security testing type that is necessary to achieve this goal?
Answer

Suggested Answer

The suggested answer is B.

Question 3 of 45

Scenario:
An international health insurance company has an advanced management system for its services that can be accessed by different types of stakeholders.
As a consequence of a deficiency in the security requirements for a new module, a data access monitoring process has not been implemented for the stakeholders involved in customer management. This feature implies that, every time any corporate stakeholder accesses a customer’s data, a record must be kept identifying the user, date and time of access as well as the reason(s) for accessing this data.
Question:
Based on the above scenario, which TWO aspects associated with the requirements could be impacted by the implementation of the solution? (Choose two.)
Answer

Suggested Answer

The suggested answer is A, B.

Question 4 of 45

Background:
CAPTCHA stands for Completely Automated Public Turing Test to Tell Computers and Humans Apart. A CAPTCHA is a program that protects websites against bots by generating and grading tests that humans can pass but current computer programs cannot. For example, humans can read distorted text, but current computer programs cannot.
Scenario:
A web application available for mobile devices provides value-added services upon free registration of future users. This application provides a series of free and other paid services. The project’s security manager has proposed to include a CAPTCHA during the registration process.
Question:
Which ONE of the following objectives of security tests for this feature is CORRECT?
Answer

Suggested Answer

The suggested answer is A.

Question 5 of 45

Scenario:
Jason is a security tester who is planning to a run system hardening. He plans to keep all the servers that he will be testing in a secure datacenter, making sure to harden these before connecting them to the internet or to an external network. He plans to install only the required software, avoiding all other unnecessary software installations.
He will also remove any components or functions he does not need, restricting access to the applications based on user roles, removing all default passwords and inspecting integrations with other applications and systems.
He plans to ensure that all the rules for the firewall are regularly audited, and that the security of remote access points and test user accounts are tested.
Question:
Which TWO of the following types of system hardening is Jason planning? (Choose two.)
Answer

Suggested Answer

The suggested answer is A, B.

40 more questions await

Unlock the full ISTQB CT-SEC question bank

5 of 45 completed11%

Choose your plan

One-time payment · No subscription · No hidden fees

Standard

Quick preparation

$25

30 days access

30 day access to all questions
Instant free updates
Highest passing rate in industry
Printable PDF download
No money-back guarantee
Best Value

Premium

Guaranteed success

$60$35

90 days access

PDF

Printable PDF download

New

Save every question as a PDF for offline study or printing.

90 day access to all questions
Instant free updates
Highest passing rate in industry
Pass guaranteed or money back

100% Money-Back Guarantee

Don't pass? Full refund.

4.9/5

Based on 4,988+ reviews

Trusted by thousands of professionals

Join certified professionals who passed their exams with Examice

Examice helped me pass my AWS certification on the first try! The questions were incredibly similar to the real exam. Comments helped me understand answers I was struggling with.
S
Sarah C.
Cloud Engineer
Great results in a short prep time. Passed on my first attempt.
D
David K.
Network Engineer
I needed to pass an exam for work, and this website delivered. The quality for the price is outstanding, and the support is really good. I passed without issues.
M
Michael R.
Security Analyst
Skeptical at first, but impressed. Every question included clear, detailed explanations.
L
Lisa M.
Solutions Architect
The guarantee gave me confidence to invest in the premium package. Turns out I didn't need it. Passed comfortably. The explanations for each answer were incredibly detailed and helped me grasp security concepts that I'd been struggling with for months.
R
Robert H.
Cybersecurity Consultant
Used Examice for my PMP certification. The questions were well structured and covered all exam domains thoroughly.
J
James T.
IT Manager
After failing my first attempt with other study materials, I switched to Examice and passed confidently on my second attempt.
A
Anna W.
Data Engineer
The premium package was worth it. 90 days of access gave me the flexibility to study when it worked for me, without feeling rushed.
E
Emily J.
DevOps Engineer
Straightforward questions that matched the real exam perfectly. Studied for two weeks and passed with a great score.
K
Karen P.
Systems Administrator

Frequently Asked Questions

Everything you need to know. Contact us for more.

Our ISTQB CT-SEC questions are based on real exam experiences and are continuously updated to match the current exam format. We maintain a +99% pass rate because our questions closely mirror what you'll see on the actual exam.

With our Premium package, you get a 100% money-back guarantee. If you don't pass your exam after studying with our materials, simply contact us with your exam results and we'll refund your purchase. Terms and conditions apply, read our full refund policy to learn more.

Our question bank is updated regularly based on feedback from recent exam takers. We typically review and update our content every week with reports about new questions or changes to the exam format.

Standard package access cannot be extended. However, Premium package gives you 90 days which is typically more than enough time to prepare thoroughly. If you need additional time, you can purchase a new package at any time.

This is a one-time payment with no recurring charges. Once you purchase, you get full access to all exam questions for the duration of your package (30 days for Standard, 90 days for Premium). No hidden fees or automatic renewals.

Pass on your first try

All 45questions · Detailed explanations · Printable PDF · 90 days access

Money-back guaranteeSecure checkout
$35

one-time payment