Software Testing Archives - iSecPrep https://www.isecprep.com/tag/software-testing/ Your Guide to IT Certification Success Mon, 24 Aug 2026 07:18:42 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 Security Test Engineer Certification: The Exam That Replaced CT-SEC https://www.isecprep.com/2026/08/21/security-test-engineer-certification-istqb-ct-ste/ Fri, 21 Aug 2026 00:00:00 +0000 https://www.isecprep.com/?p=86841 Half the study material online still describes a syllabus ISTQB retired. CT-STE replaced it in January 2025, nothing transfers automatically, and two of its nine areas carry most of the difficulty.

The post Security Test Engineer Certification: The Exam That Replaced CT-SEC appeared first on iSecPrep.

]]>

If you have been searching for the ISTQB Certified Tester Security Tester, the CT-SEC exam, there is something you need to know before you book anything: ISTQB split it. The 2016 CT-SEC syllabus became two separate credentials, and the one that exists today for hands-on work is the Certified Tester Security Test Engineer, exam code CT-STE, released in January 2025. A second credential, Security Test Analyst or CT-STA, is due to follow. Nothing carries over automatically between them. This matters because a good deal of the material still circulating online describes the old syllabus as current. This article sets out what CT-STE actually contains, what the exam costs and how it is scored, what its nine syllabus areas ask, why two of them are noticeably harder than the rest, and what you need in place before you can sit it.

What Is the ISTQB Security Test Engineer Certification?

CT-STE is ISTQB’s specialist credential for people who carry out security testing as part of a software testing practice. It sits above ISTQB Foundation Level and covers the practical execution of security testing: choosing techniques, running a security test process, applying industry standards, and reporting what you find in a way an organisation can act on.

The framing is deliberately different from a penetration testing certification. ISTQB is explicit about this.

“Penetration testing is just one aspect of security testing. ISTQB’s security testing syllabus takes a broader approach, emphasizing shift-left testing – integrating security testing from the earliest stages of software development.”

ISTQB, Certified Tester Security Test Engineer FAQ

That single sentence explains most of the syllabus. If you expect an exam about exploiting a vulnerable web application, you will be surprised by how much of CT-STE is about process, lifecycle, organisational context and reporting. The exam is aimed at making security testing a normal part of how software is built, not a specialist raid conducted at the end.

Who it is written for

Test engineers and QA leads adding a security specialism are the core audience. Security professionals sometimes take it too, usually when they need to work credibly alongside a test team and want the shared vocabulary. What it is not is an entry-level security credential, because ISTQB Foundation Level is a hard requirement before you can sit it.

Why Did CT-SEC Become CT-STE and CT-STA?

Because the 2016 syllabus tried to serve two different jobs at once. ISTQB’s own account is that the old CT-SEC combined multiple roles and activities, which made it complex and hard to navigate. The replacement separates execution from strategy: CT-STE covers carrying out security testing, and CT-STA will cover analysing business security risk and defining testing strategy.

Two consequences follow, and both catch people out. First, CT-STE was released in January 2025, so any study material describing a 2015 or 2016 syllabus is describing something else. Second, there is no grandfathering. Holding CT-SEC does not convert into either new credential; you sit the new exam or you do not hold it.

Credential Status Focus
CT-SEC, Security Tester Replaced, 2016 syllabus Combined execution and analysis in one paper
CT-STE, Security Test Engineer Current, released January 2025 Practical execution of security testing
CT-STA, Security Test Analyst Announced for 2026 Business security risk and test strategy

If you were part way through preparing for CT-SEC, the honest position is that some of your knowledge transfers and some of it does not. The Human Factors chapter that features heavily in old CT-SEC study notes has no counterpart in CT-STE. In its place you get zero trust, open-source reuse, and a full area on information security management systems. Details of the split are set out on the official CT-STE page.

What Is on the CT-STE Exam, and What Does It Cost?

CT-STE is 40 multiple choice questions in 75 minutes, costing USD $249 and delivered through Pearson VUE. The scoring is worth understanding: the 40 questions are worth 43 points in total, and the pass mark is 28 of those 43, which works out at roughly 65%. Some questions therefore carry more weight than others.

Exam detail Value
Certification ISTQB Certified Tester Security Test Engineer
Exam code CT-STE
Questions 40
Total points 43
Passing score 28 of 43, about 65%
Duration 75 minutes
Fee USD $249
Format Multiple choice
Delivery Pearson VUE
Prerequisite ISTQB Foundation Level

Forty questions in 75 minutes gives you close to two minutes each, which is comfortable by certification standards. The pressure in this exam is not the clock. It is that a third of the points come from areas asking you to analyse a situation rather than recall a definition, and analysis questions have long stems.

The mismatch between 40 questions and 43 points is worth a second thought. It means at least three questions are weighted more heavily, so a wrong answer on one of those costs more than a wrong answer elsewhere. There is no way to identify them during the exam, which is another argument for even coverage.

What Do the Nine Syllabus Areas Cover?

CT-STE publishes no percentage weightings, but it does something more useful: it publishes a teaching-time allocation in minutes and a cognitive K-level for every area. Nine areas total 1,290 minutes of teaching time, and the split tells you exactly where the syllabus thinks the difficulty lies.

Syllabus area Time Level
Security Paradigms 135 minutes K3
Security Test Techniques 150 minutes K3
The Security Test Process 120 minutes K3
Security Testing Standards and Best Practices 195 minutes K3
Adjusting Security Testing to the Organizational Context 195 minutes K4
Adjusting Security Testing to Software Development Lifecycle Models 165 minutes K4
Security Testing as Part of an Information Security Management System 105 minutes K3
Reporting Security Test Results 135 minutes K3
Security Testing Tools 90 minutes K3

What the shape tells you

Standards and Best Practices and Organizational Context tie for the largest allocation at 195 minutes each. Security Testing Tools is the smallest at 90, which is a useful corrective for anyone assuming a security testing exam will be tool-heavy. It is not: tools are the shortest area on the syllabus and are pitched at understanding categories and selection criteria rather than operating any specific product.

Security Paradigms opens the syllabus with concepts that were not in the old exam at all, including asset security levels, the role of security testing in audits, zero trust, and the security implications of reusing open-source software. Security Test Techniques then gets specific: black-box, white-box and greybox contexts, static against dynamic testing, and testing identity and access controls, data protection controls and protective technologies.

Why Are the Two K4 Areas the Hard Part?

ISTQB grades objectives by cognitive level. K3 means apply, which is what most of this syllabus asks. K4 means analyse, and only two areas reach it: Adjusting Security Testing to the Organizational Context, and Adjusting Security Testing to Software Development Lifecycle Models. Together they carry 360 of the 1,290 minutes, well over a quarter of the syllabus.

The difference is not academic. A K3 objective asks you to apply a technique you have learned. A K4 objective hands you a situation and asks you to work out which considerations apply and why, with no single obvious mapping. Those questions have longer stems, more plausible distractors, and no shortcut.

Organizational context

You are asked to analyse an organisational context and determine which aspects matter for security testing, to analyse how regulation shapes security policy and how to test that policy, and to analyse an attack scenario to identify the likely source and motivation. That last one is unusual for a testing exam and rewards people who have read incident writeups rather than only test plans.

Lifecycle models

Here you analyse how security testing activities change across different development lifecycle models, and you define and perform security regression and confirmation testing off the back of a system change. Anyone who has only worked in one delivery model will find this the thinnest ground, because the question is precisely about the differences between models.

Practical advice: give these two areas more than a proportional share of your preparation. Twenty-eight per cent of teaching time at the harder cognitive level plausibly means rather more than 28% of the difficulty.

Which Standards Does the Exam Expect You to Apply?

Four are named directly in the syllabus objectives, and the wording is “apply the concept of”, not “be aware of”. You need to know what OWASP, CWE, CVE and CVSS are, what each is for, and how a security tester would actually use them. Standards and Best Practices is one of the two largest areas at 195 minutes.

The four standards the ISTQB CT-STE exam expects you to apply: OWASP for method, CWE for flaw type, CVE for a known flaw, CVSS for severity
  • OWASP for the testing methodology and the common web application weakness categories
  • CWE, the Common Weakness Enumeration, for classifying the type of a weakness
  • CVE, the Common Vulnerabilities and Exposures list, for identifying specific known vulnerabilities
  • CVSS and the Common Weakness Scoring System for expressing severity in a comparable way

The distinction between CWE and CVE trips people up and is exactly the kind of thing a multiple choice exam tests. A CWE describes a class of weakness, such as improper input validation. A CVE identifies one concrete instance of a weakness in a specific product. Scoring then sits on top: the CVSS scoring framework gives a severity number you can compare across findings, which is what makes a report actionable.

For methodology, the OWASP Web Security Testing Guide is the closest thing to a practical companion to this part of the syllabus, and the weakness taxonomy itself is maintained as the Common Weakness Enumeration. The syllabus also asks about the advantages and disadvantages of test oracles in security testing, which is a subtler point: for a security test, knowing what the correct outcome should look like is often the hardest part of the design.

Do You Need Programming or Foundation Level First?

Foundation Level is mandatory. ISTQB requires a valid Certified Tester Foundation Level certificate before you can sit CT-STE, and there is no route around it. Programming is a different matter: ISTQB states that a technical background helps but is not required, and that the syllabus is written to be accessible regardless of programming experience.

ISTQB CT-STE prerequisites: Foundation Level required, coding not required, practical experience optional

That is a genuine design decision rather than a marketing line. Read the objectives and you find “describe how to test”, “analyze”, “evaluate” and “explain” far more often than anything requiring you to write code. Where technical depth appears, such as static and dynamic analysis tools, the objective is to understand the concepts and use cases rather than to operate a scanner.

What actually helps

  • Having sat in a real security test planning conversation, so organisational context is not hypothetical
  • Having read vulnerability reports, which makes the reporting and severity material concrete
  • Familiarity with more than one development lifecycle model, which directly serves a K4 area
  • Working knowledge of identity and access controls, since testing them is an explicit objective

If Foundation Level is the piece you are missing, that is where to start rather than here. The ISTQB Foundation Level route sets out what that exam covers, and the wider ISTQB certification catalogue shows how the specialist tracks branch off it. ISTQB’s own current listing of every active exam is kept on its certification catalogue page, which is the place to confirm a syllabus version before you buy any study material.

How Should You Prepare for CT-STE?

Use the published teaching times as your budget and the K-levels as your difficulty multiplier. Nine areas over 1,290 minutes means the syllabus itself has told you where the weight sits, and the two K4 areas deserve more than their share because analysis questions cannot be revised by memorisation.

  1. Confirm your ISTQB Foundation Level certificate is valid before anything else, because it is a hard prerequisite and there is no route around it.
  2. Discard any study material built on the 2015 or 2016 CT-SEC syllabus, since the Human Factors chapter and much else in it has no counterpart in CT-STE.
  3. Read the current syllabus end to end once without taking notes, so the shape of the nine areas is familiar before you start studying any of them in depth.
  4. Spend your largest blocks on the two K4 areas, organisational context and lifecycle models, because analysis-level questions carry long stems and plausible distractors.
  5. Learn the four named standards properly, drilling the difference between a CWE class and a CVE instance until it is automatic, then layering CVSS severity on top.
  6. Practise writing up a finding as a report, since a whole area covers reporting, confidentiality of results, and evaluating techniques for closing a vulnerability.
  7. Finish with timed practice at under two minutes a question, tracking wrong answers by syllabus area so you can see which of the nine still needs work.

The full area list with every objective is published on the CT-STE syllabus breakdown, which is the reference to check your coverage against before booking.

Frequently Asked Questions

Is the ISTQB CT-SEC Security Tester exam still available?

It has been replaced. ISTQB split the 2016 CT-SEC syllabus into CT-STE, released in January 2025, and CT-STA, scheduled for 2026. If you are choosing an ISTQB security credential today, CT-STE is the one covering practical security testing.

Does CT-SEC convert into CT-STE?

No. ISTQB states there is no automatic transfer or grandfathering between the old and new credentials. A CT-SEC holder who wants CT-STE or CT-STA has to pass that exam in the usual way.

How many questions are on the CT-STE exam?

Forty multiple choice questions in 75 minutes. They are worth 43 points in total, so a few carry extra weight, and the pass mark is 28 points, which comes out at roughly 65%.

What are the prerequisites for the CT-STE exam?

A valid ISTQB Certified Tester Foundation Level certificate is required before you can sit it. There is no experience requirement written into the entry criteria, though the syllabus assumes working familiarity with testing practice.

Do you need programming skills for this certification?

No. ISTQB says a technical background such as knowledge of network protocols and firewalls is beneficial but not mandatory, and the syllabus is written to be accessible regardless of programming experience.

How much does the CT-STE exam cost?

USD $249, booked through Pearson VUE. Prices are set regionally by ISTQB member boards, so the figure you see at checkout can differ depending on where you sit the exam.

Which syllabus area is hardest?

The two graded at K4: adjusting security testing to the organisational context, and to different lifecycle models. Together they take 360 of the syllabus’s 1,290 teaching minutes and ask you to analyse rather than apply.

Is CT-STE a penetration testing certification?

No. ISTQB positions penetration testing as one part of security testing and builds the syllabus around shift-left practice, process, standards and reporting instead. Expect far more about test design and lifecycle than about exploitation.

Does the exam cover specific security tools?

Only lightly. Security Testing Tools is the smallest area at 90 minutes and asks you to categorise tools and understand static and dynamic testing concepts, not to operate any named product.

Is the syllabus useful outside regulated industries?

Yes. ISTQB states the syllabus is not limited to any industry and explicitly addresses different regulatory contexts, including how standards apply differently in regulatory as against contractual situations.

Conclusion

The single most valuable thing to take away is that the exam most people are searching for no longer exists in the form they expect. CT-SEC was split, CT-STE is the current execution-focused credential, and nothing transfers automatically. Once you are aiming at the right target, the syllabus is unusually generous with planning information: nine areas, a published teaching time for each, and a K-level that tells you which two will hurt. Budget accordingly, get Foundation Level in place first, and learn the four named standards properly rather than in outline. Check your coverage against the current syllabus areas before you book, and let timed practice tell you which of the nine still needs work.

Rating: 0 / 5 (0 votes)

The post Security Test Engineer Certification: The Exam That Replaced CT-SEC appeared first on iSecPrep.

]]>