ISQI CTAL-ST Exam Overview:
| Certification Vendor: | iSQI / ISTQB |
| Exam Name: | ISTQB® Certified Tester Advanced Level - Security Tester |
| Exam Number: | CT-SEC (also referred to as CTAL-ST) |
| Real Exam Qty: | 45 |
| Exam Format: | Multiple-choice, Closed-book, Weighted scoring |
| Passing Score: | 65% (52 out of 80 points) |
| Certificate Validity Period: | Lifetime validity |
| Exam Duration: | 120 (+25% = 150 for non-native speakers) |
| Available Languages: | English, German, Spanish, French, Portuguese, Russian |
| Related Certifications: | CTFL (Foundation Level) CTAL-TA CTAL-TTA CTAL-TM |
| Exam Price: | USD 249–328 / EUR 220–280 |
| Recommended Training: | ISTQB Syllabus Download iSQI Accredited Training Providers |
| Exam Registration: | iSQI Official Registration Pearson VUE Test Centers |
| Exam Way: | Online remote proctored or onsite at Pearson VUE / authorized test centers |
| Pre Condition: | Valid ISTQB Certified Tester Foundation Level (CTFL) certificate; recommended 18–36 months of practical software testing experience |
| Official Syllabus URL: | https://isqi.org/ISTQB-Certified-Tester-Security-Tester-CT-SEC/CT-SEC.246 |
ISQI CTAL-ST Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| 8. Security Testing Tools | 7% | - Tool selection & integration - Types of security testing tools |
| 9. Standards and Industry Trends | 3% | - Security standards & regulations - Current trends & emerging threats |
| 5. Testing Security Mechanisms | 20% | - System hardening & vulnerability scanning - Encryption, data protection & integrity - Firewalls, IDS/IPS & network security - Authentication, authorization & access control |
| 7. Security Test Evaluation and Reporting | 10% | - Analyzing test results & risk assessment - Reporting vulnerabilities & recommendations |
| 1. The Basis of Security Testing | 10% | - Security auditing and compliance - Security risks and concepts - Information security policies & standards |
| 6. Human Factors in Security Testing | 8% | - Understanding attackers & threats - Security awareness & training validation - Social engineering risks |
| 3. Security Testing Processes | 15% | - Security test planning - Security test design & analysis - Execution, evaluation and maintenance |
| 2. Security Testing Purposes, Goals and Strategies | 12% | - Objectives and scope of security testing - Aligning testing with organizational context - Risk-based and defense approaches |
| 4. Security Testing Throughout the Software Lifecycle | 15% | - Implementation & integration testing - System, acceptance & maintenance testing - Requirements & design phase security |
We're so confident of our products that we provide no hassle product exchange.


By Sabina

