CT-STE Sample Questions

CT-STE Sample Questions & Answers

Using the right security test types and techniques carries slightly more weight, spread across asset security and zero trust, designing the test process, standards and best practices, organizational context, lifecycle adjustments, ISMS reporting, and tools.

Launch the full CT-STE simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Security Paradigm · The Concept of Zero Trust

    Case Study: SecureBank Zero Trust Implementation

    SecureBank is implementing a Zero Trust architecture. They have identified three core pillars for their testing strategy:

    1. Identity Verification
    2. Device Health
    3. Data Access Policy

    The security test engineer needs to design a test case for the 'Device Health' pillar. The requirement states: 'Access to the core banking API must be denied if the requesting device does not have the latest EDR agent installed, even if the user credentials are valid.'

    Which test procedure accurately validates this requirement?

    Show answer & explanation

    Correct answer: D

    This directly tests the negative scenario for the specific policy constraint (Device Health). It isolates the variable (EDR status) while keeping identity valid, proving the Zero Trust engine evaluates device context.

  2. Question 2Intermediate

    Security Test Techniques · Applying Security Test Types According to a Test Context

    A security team is deciding between SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) for a new web application. The application uses a complex JavaScript frontend (React) and a REST API backend. The goal is to identify runtime vulnerabilities like Broken Access Control and Server-Side Request Forgery (SSRF) before production deployment. Which approach and reasoning is correct?

    Show answer & explanation

    Correct answer: B

    DAST is superior for finding runtime and environmental issues (like permissions logic/access control) because it acts as an external attacker against the running stack. SAST struggles with logic flaws that depend on runtime context.

  3. Question 3Intermediate

    Security Test Techniques · Applying Security Testing

    You are performing security testing on an IoT device that accepts binary input over a custom TCP protocol. You want to test for buffer overflows and edge-case handling by sending malformed data packets. Which technique is most appropriate?

    Show answer & explanation

    Correct answer: D

    Fuzzing involves sending random, malformed, or unexpected data to inputs to trigger crashes or unexpected behavior. Protocol fuzzing specifically targets network protocols.

  4. Question 4Beginner

    Security Test Techniques · Applying Security Test Types According to a Test Context

    When planning a penetration test for a production banking application, which document is CRITICAL to agree upon and sign before any active testing begins to avoid legal liability and operational disruption?

    Show answer & explanation

    Correct answer: A

    The Rules of Engagement (RoE) document defines the scope, allowed techniques, timing, emergency contacts, and limitations of the test. It is the legal authorization to perform attacks that would otherwise be illegal.

  5. Question 5Advanced

    Security Test Techniques · Applying Security Testing

    Which security test technique is best suited for identifying 'Broken Object Level Authorization' (BOLA/IDOR) vulnerabilities in a REST API?

    Show answer & explanation

    Correct answer: B

    BOLA requires logic testing: User A attempts to access User B's resource IDs. This requires context (two valid sessions) and logic manipulation that automated scanners often miss.

  6. Question 6IntermediateSelect 2

    Security Test Techniques · Applying Security Test Types According to a Test Context

    Select TWO primary advantages of performing a manual security code review over using an automated SAST tool. (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    Humans can understand 'User A should not pay User B's bill', whereas tools just see data moving. Business logic flaws are the main strength of manual review.

    While tools find simple regex matches, humans can spot complex patterns where developers try to hide secrets using logic (e.g., constructing a key from three different function calls).

  7. Question 7Beginner

    Security Test Techniques · Applying Security Testing

    In the context of Threat Modeling using the STRIDE methodology, which security property is violated by a 'Spoofing' threat?

    Show answer & explanation

    Correct answer: C

    Spoofing involves pretending to be someone or something else, which is a failure of Authentication. (STRIDE mapping: Spoofing->Authentication, Tampering->Integrity, Repudiation->Non-repudiation, Information Disclosure->Confidentiality, Denial of Service->Availability, Elevation of Privilege->Authorization).

  8. Question 8Intermediate

    Security Test Techniques · Applying Security Testing

    You are testing a web application that allows users to upload profile pictures. You suspect the application might be vulnerable to Unrestricted File Upload. Which test case most effectively verifies this vulnerability?

    Show answer & explanation

    Correct answer: C

    This tests for double extensions and content-type bypass, attempting to trick the server into executing a malicious script disguised as an image.

  9. Question 9Intermediate

    The Security Test Process · The Security Test Process

    Case Study: FinCorp Risk Assessment

    FinCorp is planning a security test for their new mobile banking app. The initial risk assessment identified 'Account Takeover' as a Critical risk.

    Constraints:

    • Testing window is only 3 days.
    • Budget is limited.
    • Production data cannot be accessed.

    Based on the risk and constraints, which test planning decision is most appropriate?

    Show answer & explanation

    Correct answer: A

    Risk-based testing requires focusing limited resources on the highest risk areas. Account Takeover is primarily prevented by robust Authentication and Session Management, so these must be the priority in a short window.

  10. Question 10Beginner

    The Security Test Process · Designing Security Tests

    When designing security tests, what is the primary purpose of creating 'Misuse Cases' (or 'Abuse Cases')?

    Show answer & explanation

    Correct answer: C

    Misuse cases flip standard use cases to view the system from a malicious perspective (e.g., instead of 'User logs in', 'Attacker brute forces login'). They drive the design of negative security tests.

Ready for the real thing?

The full CT-STE simulator has every exam-style question, timed mode, and instant scoring.

Go to the CT-STE simulator →