The ISTQB CT-STE v1.0.1 exam has 40 questions, 75 minutes, and 28 of 43 points (65%) to pass. ExamCaliber has 122 free ISTQB CT-STE v1.0.1 practice questions in 3 full-length mock exams of 40 questions, 75 minutes and 65% to pass — every answer, right and wrong, carries a written rationale. No sign-up, no paywall.
The exam has 40 questions worth 43 points in total, and you need 28 points to pass (65.1%). Note that 28 is a points figure, not a question count: because three questions carry two points each, 28 points does not correspond to any fixed number of correct answers. If you lose all three two-point questions you need 28 of the remaining 37 one-point questions.
The standard time limit is 75 minutes. Candidates sitting the exam in a language that is not their native language receive a 25% extension, which gives 94 minutes. The 75-minute budget works out to just under two minutes per question on average.
75 minutes is correct. The 120-minute figure comes from a single row reading "TOTAL 120 minutes for 40 questions" inside one of ISTQB's detailed exam-structure tables; it is an artefact. The summary exam-structure table (v1.18) and the official CT-STE certification page both state 75 minutes (94 with the non-native extension). The per-question timing budget confirms it: 24 K2 questions at 1 minute, 13 K3 at 3 minutes and 3 K4 at 4 minutes add up to exactly 75 minutes.
Yes. The syllabus states that the ISTQB Foundation Level certificate must be obtained before taking the Security Test Engineer exam. It is the only formal prerequisite.
No to both. CT-STE requires no minimum years of experience and does not require CT-SEC. This differs from the older CT-SEC certification, which requires three years of relevant experience. ISTQB's own help page for this certification confusingly writes "CT-SEC" where it means CT-STE, but that is a typo, not an extra prerequisite.
They are separate certifications with separate exams. CT-SEC (Security Tester, 2016) is 45 questions, 80 points, 52 to pass, 120 minutes, and requires three years of relevant experience; it is still live and has not been formally marked as retiring. CT-STE (Security Test Engineer, 2025) is 40 questions, 43 points, 28 to pass, 75 minutes, and requires only CTFL. For someone starting now, CT-STE is the current path: a newer syllabus and a much lower entry bar. There is no grandfathering in either direction, so holding CT-SEC does not give you CT-STE.
CT-STA is a planned ISTQB Security Test Analyst certification. As of now it is not released on istqb.org, so there is no syllabus, exam format or exam date to prepare for. If you want an ISTQB security certification today, CT-STE is the one that exists.
No. The exam has 40 questions but 43 points, because three K4 questions are worth two points each. The other 37 questions are worth one point each (24 at K2 and 13 at K3). There are no K1 questions on this exam at all. Two of the three K4 questions come from the "Analyzing an Attack Scenario" learning objective (STE-5.3.1) and one from analysing the effect of SDLC models on security testing (STE-6.1.2).
There is no single global price. The exam fee is set by the ISTQB national member board or exam provider you book through, and it varies by country and by whether you book the exam alone or as part of a training course. Check the price with the member board for your region before you plan a budget.
No. The syllabus covers categories of tools rather than individual products: static and dynamic analysis, SAST, DAST, IAST, software composition analysis, vulnerability scanning, fuzzing and penetration testing tools, plus the considerations involved in selecting them. You are expected to reason about which category fits a use case, not to remember any vendor's user interface. The syllabus also notes that some security tools are restricted in certain countries and organisations.
No. The syllabus explicitly states that completion of an accredited training course is not a prerequisite for the exam. You can self-study from the syllabus and sit the exam directly, provided you already hold CTFL.
The current syllabus is version 1.0.1, dated 31 January 2025; version 1.0 was published on 18 October 2024, and ISTQB describes the certification as released in January 2025. Study only from v1.0.1. Available exam languages depend on your national member board or exam provider; English is the base language, and any translation is published by a member board rather than centrally.
ISTQB's own recommended training time for the syllabus is 1290 minutes, which is 21.5 hours of instruction spread across the nine chapters. Self-study normally takes longer than instructor-led time, so a realistic plan is roughly 30 to 40 hours including mock exams, spread over four to six weeks. Weight your time towards chapters 4, 5 and 6 (195, 195 and 165 recommended minutes), which are the most demanding parts of the syllabus.
No. None of those terms appear in the CT-STE syllabus — SBOM / Software Bill of Materials is not mentioned once, and neither are red teaming, honeypots, SIEM or Common Criteria. Several popular security-testing courses teach them, but they are outside the scope of this exam. The syllabus concentrates instead on zero trust, OWASP guidance, the CWE-to-CVE-to-CAPEC chain, STRIDE threat modelling, tool categories, ISO/IEC 27001 and ISMS integration, and GDPR.
The exam is spread almost evenly across all nine chapters, and no chapter contributes more than 7 of the 40 questions; most contribute 3 or 4. That means there is no chapter you can concentrate on to carry you through, and no chapter you can safely skip — unlike some other ISTQB specialist exams where a single chapter holds a large share of the questions. The official per-chapter breakdown is shown on the certification page.
That depends on the ISTQB national member board or exam provider you book through, not on the certification itself. Some providers offer remotely proctored online exams, others only exams at test centres or after accredited training. Check the delivery options with the provider in your region before booking.