ISTQB Specialist (CT-STE v1.0.1) Mock Exam #3
Full-length CT-STE practice exam number 3: 40 questions, 43 points, 65% to pass, 75 minutes. The chapter and K-level mix follows the official ISTQB Security Test Engineer v1.0.1 exam structure exactly — 6/7/5/4/4/4/4/3/3 questions across the nine chapters, with 24 K2, 13 K3 and 3 K4 items. This mock leans on attack scenario analysis: NIDS evidence of active reconnaissance, a denial-of-service pattern with no ransom demand, and the gap between two-week iterations and a quarterly regulatory release window. Applied questions cover reconciliation testing of accumulated permissions, CAPEC-driven test design, STRIDE information disclosure and denial of service, standards as imperfect test oracles, data localisation and outsourced testing, security regression after a library upgrade, ISMS maturity, technical impact analysis, hiding versus removing a vulnerability, and tool selection without source code. Every answer option carries a rationale.
Exam format
The ISTQB CT-STE v1.0.1 exam has 40 questions, 75 minutes, and 28 of 43 points (65%) to pass.
ExamCaliber has 122 free ISTQB CT-STE v1.0.1 practice questions in 3 full-length mock exams of 40 questions, 75 minutes and 65% to pass — every answer, right and wrong, carries a written rationale. No sign-up, no paywall.
What this mock covers
This paper draws 40 questions from 9 chapters of the ISTQB CT-STE v1.0.1 syllabus. The split below is read from the questions bound to this mock, so it is the paper you will actually sit rather than a target.
| Chapter | Questions | Share | Points |
|---|---|---|---|
| Chapter 1 · Security Paradigms | 6 | 15% | 6 |
| Chapter 2 · Security Test Techniques | 7 | 18% | 7 |
| Chapter 3 · The Security Test Process | 5 | 13% | 5 |
| Chapter 4 · Security Testing Standards and Best Practices | 4 | 10% | 4 |
| Chapter 5 · Adjusting Security Testing to the Organizational Context | 4 | 10% | 6 |
| Chapter 6 · Adjusting Security Testing to Software Development Lifecycle Models | 4 | 10% | 5 |
| Chapter 7 · Security Testing as Part of an Information Security Management System | 4 | 10% | 4 |
| Chapter 8 · Reporting Security Test Results | 3 | 8% | 3 |
| Chapter 9 · Security Testing Tools | 3 | 8% | 3 |
Scoring is weighted: 40 questions are worth 43 points, because a question at a higher cognitive level counts for more. Revise the heavier chapters first.
Cognitive levels in this mock
Each of the 40 questions is mapped to a syllabus cognitive level - K1 recall, K2 comprehension, K3 application, K4 analysis. A paper heavy on K3 asks you to apply a technique, not to name it.
- K2 - Understand24 (60%)
- K3 - Apply13 (33%)
- K4 - Analyse3 (8%)
Practise one chapter at a time
If this mock exposes a weak chapter, drill that chapter on its own before sitting another full paper.
- 1. Security Paradigms
- 2. Security Test Techniques
- 3. The Security Test Process
- 4. Security Testing Standards and Best Practices
- 5. Adjusting Security Testing to the Organizational Context
- 6. Adjusting Security Testing to Software Development Lifecycle Models
- 7. Security Testing as Part of an Information Security Management System
- 8. Reporting Security Test Results
- 9. Security Testing Tools
Other mock exams for this certification
2 more mock exams are available for ISTQB CT-STE v1.0.1, each a different selection from the same question bank.