Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by ISTQB
Exam Format
Registration
Validity
CT-STE Exam Topics and Domains
CT-STE is organized into 9 weighted domains. Expect to work with Security frameworks, Attack simulation, Automation tools, Black Duck, and more.
Security Paradigm
Asset Security Levels
Understand different security levels of assets and their corresponding protection level
Security Audits
Describe the role of security testing in the context of security audits
The Concept of Zero Trust
Understand the concept of Zero Trust
Open-Source Software (OSS)
Exemplify the concept of Open-Source Software (OSS) reuse in software development and its impacts on security testing
Security Test Techniques
Applying Security Test Types According to a Test Context
Use and apply appropriate Security Test techniques and know their strengths and limitations
Applying Security Testing
Use and apply appropriate Security Test techniques and know their strengths and limitations
The Security Test Process
The Security Test Process
Contribute to planning, designing, and executing Security Test
Designing Security Tests
Contribute to planning, designing, and executing Security Test
Standards and Best Practices
Introduction to Standards and Best Practices
Understand how Security Test standards and security best practices can be utilized for Security Test
Apply Important Standards and Best Practices for Security Testing
Understand how Security Test standards and security best practices can be utilized for Security Test
Leveraging Standards and Best Practices
Understand how Security Test standards and security best practices can be utilized for Security Test
Adjusting to the Organizational Context
The Impact of Organizational Structures in the Context of Security Testing
Adjust and perform Security Test activities accordingly to specific organization context
The Impact of Regulations on Security Policies and How to Test Them
Adjust and perform Security Test activities accordingly to specific organization context
Analyzing an Attack Scenario
Adjust and perform Security Test activities accordingly to specific organization context
Adjusting to Software Development Lifecycle Models
The Effects from Different Software Development Models on Security Testing
Adjust and perform Security Test activities accordingly to specific development methods and software development lifecycles
Security Testing During Operations and Maintenance
Adjust and perform Security Test activities accordingly to specific development methods and software development lifecycles
Security Testing as Part of an Information Security Management System
Acceptance Criteria for Security Testing
Feed Security Test results into an information security management system (ISMS) for an active security risk management
Input for an Information Security Management System (ISMS)
Feed Security Test results into an information security management system (ISMS) for an active security risk management
Improving an ISMS by Adjusted Security Testing
Feed Security Test results into an information security management system (ISMS) for an active security risk management
Reporting Test Results
Security Test Reporting
Collect, evaluate, and aggregate test results, write a detailed test report with all evidence and findings
Identifying and Analyzing Vulnerabilities
Collect, evaluate, and aggregate test results, write a detailed test report with all evidence and findings
Close Identified Vulnerabilities
Collect, evaluate, and aggregate test results, write a detailed test report with all evidence and findings
Security Test Tools
Categorization of Security Test Tools
Based on a needed Security Test approach identify proper requirements for tooling and assist in the selection of Security Test tools
Applying Security Test Tools
Based on a needed Security Test approach identify proper requirements for tooling and assist in the selection of Security Test tools
How do I earn this certification?
Passing CT-STE earns the ISTQB Certified Tester Security Test Engineer certification. It sits in the Specialist Stream - Security Testing track.
- CT-TAE - Certified Tester Test Automation EngineerAutomate security testing processes and integrate into CI/CD
- CT-AI - Certified Tester AI TestingTest AI/ML security and use AI for security testing
- CT-PT - Certified Tester Performance TestingPerformance testing often intersects with security testing
- CT-MAT - Certified Tester Mobile Application TestingMobile app security testing specialization
- CTFL-AT - Certified Tester Foundation Level - Agile TesterIntegrate security testing into Agile workflows
- CT-AcT - Certified Tester Acceptance Testing Security acceptance testing for production readiness
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for CT-STE is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2025-02-14
- Zero Trust Architecture Chapter 1 includes Zero Trust concepts and testing approaches
- Open-Source Software (OSS) Security Chapter 1 covers OSS reuse and security testing implications
- DevSecOps Integration Chapter 6 focuses on adjusting security testing to different SDLC models including DevSecOps
- ISMS Integration Chapter 7 dedicated to security testing as part of ISMS (ISO 27001)
- Security Test Tool Categories Chapter 9 dedicates 14% of exam weight to security test tools
Who should take this exam?
This exam is typically taken by Software Testers and Test Analysts.
- Practical experience in software security testing
- Understanding of security concepts and principles
- Familiarity with security testing tools and techniques
- Experience with SDLC models and development processes