ISTQB · Topic 3 of 15
Security Risks
OWASP Top 10. Types of vulnerabilities (injection, broken auth, sensitive data exposure, XXE, broken access control, security misconfig, XSS, deserialisation, vulnerable deps, insufficient logging).
6 lessons180 questions
What this topic covers
- 01Attack Surface, Authentication, and Authorization Testing480m
- 02Dynamic Analysis, Fuzzing, and Encryption Testing480m
- 03Security Risks: Maintenance Triggers, Tools, and Processes480m
- 04Security Risks: Controls, Culture, and Testing Mindset480m
- 05Test Case Update, Data Refresh, and Environment Patching480m
- 06White-Box Testing for Security Risks in Implementation Phase480m
Other topics in CT-SEC — Security Testing
The Basis of Security Testing6 lessonsBasis of Security Testing6 lessonsSecurity Testing Purposes, Goals, and Strategy5 lessonsSecurity Test Strategy6 lessonsSecurity Test Process6 lessonsSecurity Testing Processes5 lessonsTesting Security Mechanisms6 lessonsSecurity Testing Throughout the SDLC7 lessonsHuman Factors of Security Testing4 lessonsHuman Factors in Security Testing6 lessonsSecurity Test Evaluation and Reporting5 lessonsSecurity Testing Tools6 lessonsSecurity Testing Tools and Standards4 lessonsStandards and Industry Trends6 lessons