About the Exam

ISTQB CT-SEC is an advanced security testing certification for people with some experience in security testing who want to deepen their expertise. It covers planning, performing, and evaluating security tests from risk, requirements, vulnerability, and human factors perspectives, along with security testing tools and standards. Candidates are expected to hold the ISTQB Foundation Level certificate and have relevant practical, academic, or consulting experience. Passing demonstrates the ability to align security test activities with the software lifecycle and assess security threats and test coverage in context.

Exam Topics

  • The Basis of Security Testing13%
  • Security Testing Processes18%
  • Security Testing Throughout the Software Lifecycle29%
  • Testing Security Mechanisms31%
  • Human Factors in Security Testing13%
  • Security Test Evaluation and Reporting9%
  • Security Testing Tools7%
  • Standards and Industry Trends5%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated May 14, 2026 at 10:52 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Security Testing Processes

Which ONE of the following security vulnerabilities can be found through structural testing during component testing?

Explanation

Structural testing examines a component’s internal code and implementation. It can reveal deliberately inserted malicious code, including code introduced by an internal employee or contractor. The ISTQB Security Tester syllabus specifically identifies this as a vulnerability that can be detected and corrected through structural testing.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Security Testing Throughout the Software Lifecycle

Sophie is assessing the security requirements in user stories to confirm that the security-related elements of users’ needs are adequately addressed. She is also determining the most practical approach for developing the application securely.

During which software development life cycle stage should this activity occur?

Explanation

The requirements stage establishes and analyzes functional and nonfunctional requirements, including security requirements derived from user needs and user stories. Identifying these needs early ensures that security constraints guide later design and development work.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Security Testing Processes

In the scenario described, which ONE of the following test-environment attributes is missing?

Explanation

A properly designed test environment must be restorable — capable of being returned to a known, consistent baseline state after each test run or between test cycles — so that subsequent tests, including regression checks and defect-fix verification, start from reproducible conditions. When an environment lacks a reliable mechanism (such as snapshots, backups, or a reset procedure) to revert configuration and data changes introduced during testing, results become inconsistent and defects become hard to reproduce or confirm as fixed, which is precisely the gap the restorable attribute is meant to cover.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Security Testing Processes

Which ONE of the following options correctly identifies the security testing type needed to accomplish this objective?

Explanation

Authorization testing verifies that users can access only the functions permitted by their assigned roles. Confirming that a non-admin user cannot access an administrator-only user-editing endpoint tests enforcement of role-based authorization and prevents vertical privilege escalation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Human Factors in Security Testing

Annie is setting up a fake email ID to pose as a company’s CTO. She is also using social media, instant messaging, and SMS to deceive potential victims into revealing sensitive information.

Which ONE of the following attacks is she planning?

Explanation

Social engineering uses impersonation and deceptive communications to manipulate people into disclosing sensitive information. Posing as an executive through email and contacting targets through social media, instant messaging, and SMS are common social-engineering tactics.

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
The Basis of Security TestingSecurity Testing ProcessesSecurity Testing Throughout the Software LifecycleTesting Security MechanismsHuman Factors in Security TestingSecurity Test Evaluation and ReportingSecurity Testing ToolsStandards and Industry Trends
Know a question that should be here? Contribute to this exam
Back home