ISTQB Certified Tester Foundation Level (CTFL) — Questions and Answers
Question 1: Which of the following activities is a key part of the risk analysis (or risk assessment) phase within a risk-based testing approach?
- Implementing changes to the code to fix the identified risks.
- Executing all planned test cases and logging the results.
- Purchasing new test automation tools for the project.
- Determining the likelihood and impact of each identified risk item. (Correct answer)
Correct answer: Determining the likelihood and impact of each identified risk item.
The risk analysis or assessment phase is specifically concerned with evaluating the identified risks to determine their level. This is typically done by assessing two key dimensions: the likelihood (probability) of the risk occurring and the potential impact (or harm) if it does occur. [6, 7, 11] This assessment allows the team to prioritize the risks for mitigation and testing. [3]
Question 2: Which ISTQB white-box coverage criterion subsumes statement coverage?
- Neither A nor B
- Both A and B (Correct answer)
- Path coverage
- Decision coverage
Correct answer: Both A and B
Both decision coverage and path coverage subsume statement coverage because exercising all branches or all paths necessarily executes all reachable statements.
Question 3: Static testing applied to executable code (as opposed to source code documents) typically involves which of the following?
- Analyzing bytecode or compiled output with static analysis tools (Correct answer)
- Running unit tests against the compiled binary
- Applying equivalence partitioning to identify test inputs
- Using profilers to detect memory leaks at runtime
Correct answer: Analyzing bytecode or compiled output with static analysis tools
Static analysis can be applied to compiled code (bytecode, object code) using tools that analyze its structure without executing it.
Question 4: Which test type evaluates quality characteristics such as performance, security, and usability?
- Regression testing
- Non-functional testing (Correct answer)
- Structural testing
- Functional testing
Correct answer: Non-functional testing
Non-functional testing evaluates how well the system performs its functions, covering quality attributes like performance, security, reliability, and usability.
Question 5: At which test level are user stories most commonly used as the test basis in Agile development?
- System testing
- Integration testing
- Component testing
- Acceptance testing (Correct answer)
Correct answer: Acceptance testing
In Agile, acceptance testing often uses user stories and acceptance criteria as the test basis to validate business value from the user's perspective.
Question 6: Which of the following is a key risk when introducing a test automation tool into an organization?
- Automated testing eliminates the need for test design
- Test automation tools cannot be integrated with CI/CD pipelines
- Unrealistic expectations about the benefits automation will deliver (Correct answer)
- Automated tests always run slower than manual tests
Correct answer: Unrealistic expectations about the benefits automation will deliver
Unrealistic expectations are a leading risk because teams may overestimate ROI and underestimate setup effort, leading to abandoned automation efforts.
Question 7: A test team is applying a risk-based testing strategy to an e-commerce application. The team identifies that the payment processing module is built with complex, new technology and a failure would have a severe financial impact. According to risk-based principles, how should this information primarily influence the test strategy?
- Allocate more experienced testers and conduct more in-depth testing on this module. (Correct answer)
- Assign only junior testers to the module to see how intuitive it is.
- Delay testing of this module until all other features have been fully tested.
- Decrease the amount of testing for this module to fast-track the release.
Correct answer: Allocate more experienced testers and conduct more in-depth testing on this module.
Risk-based testing directs the testing effort to be proportional to the level of risk. [13] A module with high complexity (increasing likelihood of failure) and severe financial impact is considered high-risk. Therefore, it requires more intensive and in-depth testing, often carried out by more experienced personnel, to mitigate the risk of failure in the live environment. [4, 16]
Question 8: According to ISTQB, maintenance testing is triggered by:
- The initial development phase of a new system
- User acceptance testing failures
- Modifications, migrations, or retirement of an existing system (Correct answer)
- Performance degradation detected during operations
Correct answer: Modifications, migrations, or retirement of an existing system
Maintenance testing is performed when an existing operational system undergoes changes (enhancements, fixes), migration to another platform, or retirement.
Question 9: Which ISTQB testing principle warns against relying solely on one testing technique or focusing testing only on familiar areas?
- Defects cluster together
- Pesticide paradox (Correct answer)
- Absence-of-errors fallacy
- Testing is context dependent
Correct answer: Pesticide paradox
The pesticide paradox states that repeatedly running the same tests will eventually stop finding new defects, requiring tests to be regularly reviewed and revised.
Question 10: What does 'severity' measure in the context of ISTQB defect management?
- The degree of impact the defect has on the system or component under test (Correct answer)
- The difficulty of reproducing the defect
- The number of users affected by the defect
- How urgently the defect must be fixed relative to business deadlines
Correct answer: The degree of impact the defect has on the system or component under test
Severity reflects the technical impact on the system's functionality, distinguishing it from priority which reflects business urgency.
Question 11: Which statement best describes the relationship between test levels and development phases in a sequential model?
- Each test level corresponds to a specific development activity (Correct answer)
- All test levels are executed simultaneously
- Test levels are independent of development phases
- Test levels are only relevant in agile models
Correct answer: Each test level corresponds to a specific development activity
In sequential models like the V-model, each test level (unit, integration, system, acceptance) corresponds to a specific development phase (detailed design, high-level design, requirements, business needs).
Question 12: What is the role of a 'test coordinator' in a large project with multiple test teams?
- To approve software releases based on test results
- To write all test cases for the project
- To coordinate test activities, resources, and communications across teams (Correct answer)
- To execute all automated regression tests
Correct answer: To coordinate test activities, resources, and communications across teams
A test coordinator synchronizes activities, resources, and communication across multiple test teams.
Question 13: A tester finds that repeated use of the same test cases over time stops detecting new defects. Which ISTQB principle explains this?
- Testing is context dependent
- Defects cluster together
- Early testing saves time and money
- Pesticide paradox (Correct answer)
Correct answer: Pesticide paradox
The pesticide paradox states that if the same tests are repeated, they eventually stop finding new bugs and must be reviewed and updated.
Question 14: A team is developing software using continuous integration. Which testing practice is most essential to support this approach?
- User acceptance testing after each commit
- Full system testing performed weekly
- Automated regression tests that run on every build (Correct answer)
- Manual exploratory testing after each build
Correct answer: Automated regression tests that run on every build
Automated regression testing is essential for CI because it provides rapid feedback after each build, detecting integration issues early.
Question 15: Which role is typically responsible for initially assigning priority to a defect in ISTQB defect management?
- Release manager
- Tester who found the defect
- Developer
- Project manager or product owner (Correct answer)
Correct answer: Project manager or product owner
Priority is a business decision typically made by the project manager or product owner, reflecting business impact rather than technical severity.
Question 16: In a defect report, the 'test environment' field should include:
- Only the operating system version
- The tester's workstation name only
- The production environment specifications
- Hardware, OS, browser/app version, database version, and any other configuration relevant to reproduction (Correct answer)
Correct answer: Hardware, OS, browser/app version, database version, and any other configuration relevant to reproduction
Full environment details allow developers to reproduce the defect in matching conditions, especially important for environment-specific issues.
Question 17: Which practice best supports the ISTQB principle that 'exhaustive testing is impossible'?
- Using risk and priority to select the most valuable subset of tests (Correct answer)
- Automating all test cases to run faster
- Hiring more testers to achieve complete coverage
- Repeating the same test cases to find more defects
Correct answer: Using risk and priority to select the most valuable subset of tests
Since complete testing is infeasible, testers use risk-based prioritization and techniques like equivalence partitioning to maximize defect detection within constraints.
Question 18: What is the primary benefit of involving testers in requirements reviews?
- Requirements reviews replace functional testing
- Testers can write the requirements more accurately
- Testers can estimate development effort
- Defects in requirements are detected and corrected earlier (Correct answer)
Correct answer: Defects in requirements are detected and corrected earlier
Early tester involvement in requirements reviews enables detection of ambiguous, incomplete, or contradictory requirements before they cascade into expensive downstream defects.
Question 19: In any software development lifecycle model, which of the following is considered a characteristic of good testing?
- For every development activity, there is a corresponding testing activity. (Correct answer)
- Testers are only involved after the coding phase is complete to ensure their independence.
- Test level objectives are kept generic to allow for flexibility across the project.
- Test analysis and design are postponed until a stable build is available for execution.
Correct answer: For every development activity, there is a corresponding testing activity.
A key principle of 'Testing Throughout the Lifecycle' is that testing is not a single phase but a set of activities that run in parallel with development. For every development activity (e.g., gathering requirements, creating a design), there should be a corresponding test activity (e.g., reviewing requirements for testability, designing acceptance tests).
Question 20: Which of the following best describes a model-based testing tool?
- A tool that manages the test environment configuration
- A tool that simulates network latency for performance testing
- A tool that measures how closely actual results match expected results
- A tool that generates test cases automatically from a behavioral model of the system (Correct answer)
Correct answer: A tool that generates test cases automatically from a behavioral model of the system
Model-based testing tools derive test cases from formal models (e.g., state machines, decision tables) that represent expected system behavior.
Question 21: What is the main purpose of a static analysis tool in the context of static testing?
- To execute the code and observe its runtime behavior
- To generate test cases automatically from requirements
- To measure the performance of the software under load
- To analyze source code or models without executing them (Correct answer)
Correct answer: To analyze source code or models without executing them
Static analysis tools examine code or models without execution, identifying potential defects like unreachable code or violations of coding standards.
Question 22: In test process improvement using TMMi, what does reaching Maturity Level 3 indicate?
- Testing metrics are used to quantitatively control the process
- Testing is ad hoc and unpredictable
- Testing processes are defined, documented, and standardized across the organization (Correct answer)
- Testing is fully automated with no manual intervention
Correct answer: Testing processes are defined, documented, and standardized across the organization
TMMi Level 3 (Defined) means the organization has established and documented standard testing processes that are consistently applied across projects.
Question 23: Which metric is MOST useful for tracking whether testing is progressing according to plan?
- Percentage of planned test cases executed vs. actual (Correct answer)
- Number of test environments configured
- Total lines of code tested
- Number of defects found per tester
Correct answer: Percentage of planned test cases executed vs. actual
Comparing planned vs. actual test case execution gives a direct measure of testing progress against the plan.
Question 24: What is the primary goal of Modified Condition/Decision Coverage (MC/DC), a technique often required for safety-critical systems?
- To execute every statement in the software at least once.
- To ensure that every function in the code has been called with every possible parameter value.
- To show that each condition within a decision can independently affect the outcome of that decision. (Correct answer)
- To test every possible combination of conditions within a decision.
Correct answer: To show that each condition within a decision can independently affect the outcome of that decision.
The goal of MC/DC is to demonstrate that each individual condition within a complex decision can, on its own, affect the decision's outcome. This is achieved by creating test pairs where only one condition's value is changed, and this change causes the decision's outcome to flip, proving the independence of that condition.
Question 25: Which factor is LEAST likely to be considered when determining the entry criteria for system testing?
- Availability of a stable test environment
- The programming language used to develop the software (Correct answer)
- Completion of unit and integration testing
- Sign-off on system test plans and test cases
Correct answer: The programming language used to develop the software
The programming language is a development concern and does not typically affect system test entry criteria.
Question 26: A software release must be made despite not all planned tests being executed. The test manager should:
- Document the untested risks and communicate them to stakeholders for an informed release decision (Correct answer)
- Run only automated tests and ignore manual test results
- Secretly mark untested items as passed to meet the deadline
- Refuse to approve the release under any circumstances
Correct answer: Document the untested risks and communicate them to stakeholders for an informed release decision
The test manager should document residual risks from incomplete testing and communicate them so stakeholders can make an informed go/no-go decision.
Question 27: In the ISTQB Advanced Level Test Manager syllabus, what is the purpose of a product risk analysis?
- To identify what could go wrong with the product and use that to guide test prioritization (Correct answer)
- To replace functional testing with risk-based regression only
- To allocate defect budgets across teams
- To document which features carry legal liability for the vendor
Correct answer: To identify what could go wrong with the product and use that to guide test prioritization
Product risk analysis identifies potential failure modes in the system under test and uses them to focus testing where the consequences of failure are greatest.
Question 28: A test engineer wants to record a user interaction with a web application and replay it later. Which tool type supports this?
- Requirement management tool
- Coverage measurement tool
- Defect management tool
- Capture/replay tool (Correct answer)
Correct answer: Capture/replay tool
Capture/replay tools record user interactions with a system and allow them to be replayed automatically during regression testing.
Question 29: A password field requires 8 to 16 characters. Using 3-value BVA, which set of test values is complete?
- 7, 8, 16, 17
- 8, 12, 16
- 7, 8, 9, 15, 16, 17 (Correct answer)
- 7, 9, 15, 17
Correct answer: 7, 8, 9, 15, 16, 17
3-value BVA tests the value below, at, and above each boundary: 7, 8, 9 for the lower boundary and 15, 16, 17 for the upper boundary.
Question 30: Which of the following statements about the V-model is TRUE?
- Each development phase has a corresponding testing phase (Correct answer)
- Testing and development phases overlap completely in the V-model
- The V-model is only suitable for agile projects
- Testing activities only begin after all development is complete
Correct answer: Each development phase has a corresponding testing phase
The V-model maps each development phase (requirements, design, coding) to a corresponding test level (acceptance, integration/system, unit) on the right side of the 'V'.
Question 31: What is a 'test charter' commonly used for in exploratory testing?
- Documenting the final test results for sign-off
- Assigning testers to specific test levels
- Listing all test cases to be executed during a sprint
- Defining the scope, objective, and approach for a time-boxed exploratory session (Correct answer)
Correct answer: Defining the scope, objective, and approach for a time-boxed exploratory session
A test charter provides structure for exploratory testing by defining what to explore, the goal of the session, and the approach, within a time-boxed session.
Question 32: Which maintenance testing trigger is caused by changes to the operating environment rather than to the software itself?
- Perfective maintenance
- Corrective maintenance
- Preventive maintenance
- Adaptive maintenance (Correct answer)
Correct answer: Adaptive maintenance
Adaptive maintenance testing is triggered when the software must be adapted to changes in its environment, such as OS upgrades or hardware changes.
Question 33: A project team conducts a review where participants receive the document 24 hours in advance and each person independently identifies defects before the meeting. Which review phase does the independent preparation represent?
- Issue communication and analysis
- Individual review (preparation) (Correct answer)
- Review initiation
- Review planning
Correct answer: Individual review (preparation)
Individual review or preparation is the phase where each reviewer independently examines the work product before the group meeting.
Question 34: Which statement about non-functional testing is MOST accurate according to ISTQB?
- Non-functional testing only applies at the system test level
- Non-functional testing can only begin after all functional testing is complete
- Non-functional testing evaluates 'how well' the system performs, covering qualities like speed, security, and usability (Correct answer)
- Non-functional testing is always less important than functional testing
Correct answer: Non-functional testing evaluates 'how well' the system performs, covering qualities like speed, security, and usability
Non-functional testing measures quality characteristics that describe how well the system behaves, and can be applied at any test level.
Question 35: In ISTQB terminology, what distinguishes alpha testing from beta testing?
- Alpha testing uses white-box techniques; beta testing uses black-box techniques
- Alpha testing is conducted at the developer's site; beta testing is conducted at customer sites or in the field (Correct answer)
- Alpha testing focuses on functional requirements; beta testing focuses on performance
- Alpha testing is done by developers; beta testing is done by independent testers
Correct answer: Alpha testing is conducted at the developer's site; beta testing is conducted at customer sites or in the field
Alpha testing is performed at the developing organization's own facilities, while beta testing is performed by customers or end users at their own sites in a real environment.
Question 36: Which of the following BEST explains why static testing is considered complementary to dynamic testing rather than a replacement?
- Dynamic testing can be fully automated while static testing always requires human effort
- Static testing is only effective on requirements, while dynamic testing only applies to code
- Static testing is more expensive and thus reserved for critical defects only
- Static testing finds defects in work products, but dynamic testing can reveal failures caused by the interaction of components at runtime (Correct answer)
Correct answer: Static testing finds defects in work products, but dynamic testing can reveal failures caused by the interaction of components at runtime
Static testing finds defects in artifacts early, but runtime interaction failures, timing issues, and environmental problems require dynamic testing to expose.
Question 37: Which of the following is a primary objective of Maintenance Testing?
- To verify that modifications in an operational system have not introduced adverse side effects. (Correct answer)
- To test a new system from scratch before its initial deployment.
- To confirm that a new developer understands the existing system architecture.
- To verify that new functionality has been added as per the initial project plan.
Correct answer: To verify that modifications in an operational system have not introduced adverse side effects.
Maintenance testing is performed on an existing operational system when it is modified. A key objective is to perform regression testing to ensure that changes (like fixes or enhancements) have not negatively impacted unchanged parts of the system.
Question 38: Which of the following best describes the role of a 'test oracle' in automated testing?
- A tool plugin that generates test cases from requirements
- A configuration file that defines the test environment settings
- A database that stores historical test results for trend analysis
- A mechanism that determines whether the actual test outcome matches the expected result (Correct answer)
Correct answer: A mechanism that determines whether the actual test outcome matches the expected result
A test oracle is the mechanism — whether a rule, expected value, or reference system — used to decide if a test has passed or failed.
Question 39: In the context of a sequential software development lifecycle model, such as the V-model, when should test analysis and design for a specific test level ideally begin?
- As soon as the development activities for the corresponding level are underway. (Correct answer)
- During the execution phase of the previous test level.
- After the code for that level has been fully developed and passed to the test team.
- Once the entire system has been built and is ready for system testing.
Correct answer: As soon as the development activities for the corresponding level are underway.
A fundamental principle of testing throughout the lifecycle is that for every development activity, there is a corresponding testing activity. Test analysis and design for a given test level should begin during the corresponding development activity, not after it is complete. For example, acceptance test design should start during the requirements definition phase.
Question 40: In white-box testing, what does a 'du-path' represent in data flow analysis?
- A path through a data store to a user interface
- A path from where a variable is defined to where it is used (Correct answer)
- A path that defines two variables simultaneously
- A path from a variable definition to its undefinition
Correct answer: A path from where a variable is defined to where it is used
A du-path (definition-use path) traces the execution path from where a variable is defined (assigned) to where it is subsequently used.
ISTQB Certified Tester Foundation Level (CTFL)
The ISTQB CTFL exam validates foundational knowledge of software testing concepts, techniques, and processes, recognized internationally as the standard entry-level testing certification.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds