ExamDumpster

Free CT-STE sample questions

Real questions from the Certified Tester Security Test Engineer practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A financial institution is migrating from a traditional perimeter-based security model to a Zero Trust Architecture (ZTA) following NIST SP 800-207 guidelines. The security test engineer is designing a test strategy to validate the 'Never Trust, Always Verify' principle for a critical internal banking application. The application previously relied solely on network segmentation (VLANs) for security. Which testing approach best validates the core Zero Trust requirement for this migration?

Question 2Choose one

During a security audit of an e-commerce platform, the lead auditor requests evidence of 'Asset Security Levels' implementation. You need to demonstrate that data protection mechanisms are aligned with data sensitivity. Given the classification scheme below: - **Public**: Marketing data - **Internal**: Employee directories - **Confidential**: Customer PII - **Restricted**: Payment Card Data (PCI) Which test scenario provides the strongest evidence of correct implementation?

Question 3Choose one

True or False: A security audit is primarily a dynamic activity that involves executing active attacks against a system to find vulnerabilities, whereas security testing is a static verification of compliance against a checklist.

Question 4Choose one

A development team is heavily utilizing Open-Source Software (OSS) libraries in a new microservice. As the Security Test Engineer, you are concerned about supply chain attacks and transitive dependencies. Which activity should be integrated into the CI/CD pipeline to specifically address this risk?

Question 5Choose one

You are defining the security test strategy for a healthcare application handling Patient Health Information (PHI). The organization requires that no production data be used in lower environments (Dev/Test). What is the most appropriate approach for creating test data that maintains functional validity while satisfying security paradigms regarding data sensitivity?

Question 6Choose one

Case Study: SecureBank Zero Trust Implementation SecureBank is implementing a Zero Trust architecture. They have identified three core pillars for their testing strategy: 1. Identity Verification 2. Device Health 3. Data Access Policy The security test engineer needs to design a test case for the 'Device Health' pillar. The requirement states: 'Access to the core banking API must be denied if the requesting device does not have the latest EDR agent installed, even if the user credentials are valid.' Which test procedure accurately validates this requirement?

Question 7Choose one

A security team is deciding between SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) for a new web application. The application uses a complex JavaScript frontend (React) and a REST API backend. The goal is to identify runtime vulnerabilities like Broken Access Control and Server-Side Request Forgery (SSRF) before production deployment. Which approach and reasoning is correct?

Question 8Choose one

You are performing security testing on an IoT device that accepts binary input over a custom TCP protocol. You want to test for buffer overflows and edge-case handling by sending malformed data packets. Which technique is most appropriate?

Question 9Choose one

When planning a penetration test for a production banking application, which document is CRITICAL to agree upon and sign before any active testing begins to avoid legal liability and operational disruption?

Question 10Choose one

Which security test technique is best suited for identifying 'Broken Object Level Authorization' (BOLA/IDOR) vulnerabilities in a REST API?

10 more free samples are waiting

Create a free account to unlock the whole CT-STE sample bank, or get full access to all 250 practice questions in the simulator.

Create account