Quality Assurance & Compliance Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Quality Assurance & Compliance flashcards as text
Which principle states that testing can show the presence of defects but cannot prove their absence?
Answer: Dijkstra's testing principle
Dijkstra stated that testing reveals existing bugs but a passing test suite cannot guarantee a system is defect-free.
A ServiceNow developer is told that a scoped application must be HIPAA-compliant. Which of the following is MOST important to implement?
Answer: Encryption of PHI fields and strict role-based access controls
HIPAA compliance requires protecting Protected Health Information (PHI) through encryption and strict access controls to limit exposure.
What is the 'pesticide paradox' in software testing?
Answer: Repeatedly running the same tests eventually finds no new bugs because defects develop immunity
The pesticide paradox describes how repeatedly executing the same test cases stops finding new defects; tests must be regularly reviewed and updated.
In the context of CAD application development, which practice helps ensure that role assignments follow the principle of least privilege?
Answer: Granting users only the minimum permissions needed to perform their job
Least privilege limits user permissions to what is strictly necessary, reducing the attack surface and limiting damage from compromised accounts.
Which artifact is typically produced at the end of a test cycle to summarize test execution results, defects found, and overall quality status?
Answer: Test summary report
A test summary report consolidates test results, defect metrics, and coverage data to communicate quality status to stakeholders.
When performing static code analysis on a ServiceNow application, what category of issue is most commonly detected?
Answer: Potential security vulnerabilities and coding standard violations without executing the code
Static analysis inspects source code without running it, catching issues like injection risks, dead code, and style violations.
A team wants to measure what percentage of the application code is exercised during testing. Which metric should they track?
Answer: Test coverage (code coverage)
Code coverage measures the percentage of source code lines, branches, or paths exercised by the test suite, indicating testing thoroughness.