Security Attack
A security attack is an intentional attempt to exploit vulnerabilities in a system to compromise confidentiality, integrity, availability, or other security objectives.
“An attempt to gain unauthorized access to a component or system, resources, information, or an attempt to compromise system integrity.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Security Attack?
Attackers use various techniques to gain unauthorized access, disrupt services, steal information, or manipulate system behavior.
Intentional action: Performed to exploit system weaknesses.
Multiple objectives: May target data, services, or infrastructure.
Testing relevance: Security testing simulates attacks to evaluate defenses.
Real World Example
An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.
The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Security attack points testing toward that hostile or risky behavior.
The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.
The team strengthens the controls because Security attack helps them test the product from the perspective of misuse, not only normal customer journeys.
Practice Questions
Question 1
Which statement BEST describes Security attack in the context of ISTQB terminology?
Question 2
A tester needs to explain Security attack to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Security Attack. Test your understanding with topic-specific questions in our Mock Exams.