ISTQB Security Testing Glossary
Attack vectors, vulnerabilities, and the testing techniques used to find them — the vocabulary of the ISTQB Security Tester syllabus.
62 terms in this topic
About this topic
Source: ISTQB Certified Tester Security Tester (CT-SEC)
Security testing evaluates whether a system protects data and maintains functionality as intended when under attack. These terms come from the ISTQB Security Tester syllabus rather than the Foundation Level, and they are the vocabulary you need once testing moves past 'does it work' to 'can it be made to fail on purpose'.
The field organises around the classic triad of confidentiality, integrity, and availability. Confidentiality means information is disclosed only to those authorised to see it; integrity means data cannot be altered undetectably; availability means the system remains usable when legitimate users need it. Most named attacks map onto an attempt to break one of the three.
A vulnerability is a weakness that an attacker can exploit; a threat is the potential cause of an unwanted incident; an attack vector is the path taken to reach the target. Testing techniques range from static application security testing, which analyses source code without running it, through dynamic and interactive application security testing, to penetration testing, where a tester actively attempts to breach a running system under controlled conditions.
Industry classification schemes appear throughout: Common Vulnerabilities and Exposures catalogues specific known flaws, Common Weakness Enumeration catalogues the underlying weakness types, and the Common Vulnerability Scoring System assigns severity. Knowing which scheme describes which layer is a common point of confusion.
Foundation Level touches security only as one non-functional test type. If you are preparing for CTFL, you need to recognise security testing as a test type and understand where it fits in the lifecycle — the depth here belongs to the specialist certification.
What this topic covers
- Attacks and attack vectors
- Vulnerabilities and weaknesses
- SAST, DAST and IAST
- Penetration testing
- CVE, CWE and CVSS
- Security policies and audits
Terms in Security Testing
Tap any term to read its full definition and examples.
62 terms
- account harvesting
- anti-malware
- attack vector
- attacker
- authentication
- authenticity
- authorization
- availability
- botnet
- code injection
- common attack pattern enumeration and classification
- common vulnerabilities and exposures
- common vulnerability scoring system
- common weakness enumeration
- common weakness scoring system
- computer forensics
- confidentiality
- cross-site scripting
- data obfuscation
- data privacy
- demilitarized zone
- denial of service
- dynamic application security testing
- encryption
- ethical hacker
- fault attack
- firewall
- fuzz testing
- hacker
- hashing
- information assurance
- information security
- insider threat
- integrity
- interactive application security testing
- intrusion detection system
- level of intrusion
- malware
- malware scanning
- network zone
- non-repudiation
- password cracking
- penetration testing
- pharming
- phishing
- reconnaissance
- salting
- script kiddie
- security
- security attack
- security audit
- security policy
- security procedure
- security risk
- security testing
- social engineering
- static application security testing
- system hardening
- vulnerability
- vulnerability scanner
- vulnerability scanning
- weakness
Test your knowledge with real ISTQB-style questions
Sit a full-length ISTQB CTFL practice test and see how well you’ve mastered this topic.
Or read questions with worked answers, or take a practice drill by chapter or K-level.