ISTQB Certified Tester Foundation Level (CTFL) — Questions and Answers
Question 1: What is a compliance management system in Software Testing practice?
- A government reporting requirement
- A software application only
- An optional business tool
- A structured framework of policies, procedures, and controls that ensure regulatory adherence (Correct answer)
Correct answer: A structured framework of policies, procedures, and controls that ensure regulatory adherence
This is fundamental to Software Testing practice. A structured framework of policies, procedures, and controls that ensure regulatory adherence represents the professional standard for regulatory in the Software Testing certification framework.
Question 2: Which statement correctly describes the difference between risk avoidance and risk reduction?
- Avoidance and reduction are interchangeable terms
- Avoidance eliminates the risk entirely; reduction lowers its probability or impact (Correct answer)
- Avoidance transfers the risk; reduction accepts it
- Avoidance lowers probability; reduction lowers impact only
Correct answer: Avoidance eliminates the risk entirely; reduction lowers its probability or impact
Risk avoidance removes the cause of the risk completely (e.g., dropping a feature), while risk reduction takes actions that make the risk less likely or less harmful.
Question 3: A financial application crashes with a stack overflow error only after running for 72 hours in production. Which testing approach is designed to detect this class of defect?
- Spike testing
- Soak (endurance) testing (Correct answer)
- Smoke testing
- Exploratory testing
Correct answer: Soak (endurance) testing
Soak testing runs the system under normal load for an extended period to uncover memory leaks, resource exhaustion, and other degradation issues that only appear over time.
Question 4: Why is continuous professional development important for software testing professionals?
- Technology, methodologies, and tools evolve constantly, requiring ongoing learning to remain effective (Correct answer)
- It is only required for testers seeking management roles
- It guarantees salary increases
- It is only necessary for testers working in regulated industries
Correct answer: Technology, methodologies, and tools evolve constantly, requiring ongoing learning to remain effective
The software testing field evolves rapidly with new tools, methodologies, and technologies, making continuous learning essential for professional effectiveness.
Question 5: What is 'publication bias' and why is it relevant to evidence-based software testing?
- The preference of journals for papers with large datasets
- A systematic error in code coverage measurement tools
- The tendency for positive results to be published more often, skewing the available evidence (Correct answer)
- A bias introduced when testers know which version of code they are testing
Correct answer: The tendency for positive results to be published more often, skewing the available evidence
Publication bias inflates apparent effectiveness of techniques because negative or null results are less likely to be published.
Question 6: Which of the following is NOT typically included in a test plan?
- Features to be tested
- Risks
- Schedule
- Incident reports (Correct answer)
Correct answer: Incident reports
A test plan outlines the scope, objectives, resources, and schedule of testing activities. It typically includes features to be tested, risks, and the testing schedule. Incident reports, which document defects found during testing, are outputs of the test execution phase and are usually managed separately, though their reporting process might be defined within the test plan.
Question 7: What is 'shift-left testing' in modern software development?
- Moving testing activities earlier in the development lifecycle (Correct answer)
- Testing on the left side of the screen layout first
- Reducing the number of test cases to speed delivery
- Shifting test responsibilities from QA to operations
Correct answer: Moving testing activities earlier in the development lifecycle
Shift-left testing moves testing activities earlier in the SDLC so defects are caught sooner when they are cheaper to fix.
Question 8: What is the primary purpose of a Verification and Validation (V&V) plan in safety-critical software testing under IEC 62304?
- To schedule regression testing cycles
- To ensure the software meets specified requirements and its intended use (Correct answer)
- To document test automation scripts
- To track developer code coverage metrics
Correct answer: To ensure the software meets specified requirements and its intended use
IEC 62304 V&V plans ensure medical device software is built correctly (verification) and fulfills its intended purpose (validation).
Question 9: Which qualitative risk analysis output is used to rank risks so teams can decide which to address first?
- Monte Carlo simulation results
- Decision tree analysis
- Risk probability-impact matrix (Correct answer)
- Expected monetary value (EMV)
Correct answer: Risk probability-impact matrix
The probability-impact matrix plots risks on a grid and produces a ranked priority list without requiring numerical monetary data.
Question 10: How do Software Testing professionals ensure compliance in daily practice?
- By integrating compliance requirements into standard operating procedures and regular audits (Correct answer)
- By memorizing all regulations
- By hiring a compliance officer
- Compliance is checked only annually
Correct answer: By integrating compliance requirements into standard operating procedures and regular audits
This is fundamental to Software Testing practice. By integrating compliance requirements into standard operating procedures and regular audits represents the professional standard for regulatory in the Software Testing certification framework.
Question 11: A tester is asked to test a module written by a close friend. What is the professionally correct approach?
- Refuse to test it without explanation
- Disclose the relationship to the project manager and ask for reassignment if objectivity may be compromised (Correct answer)
- Test it normally but be lenient on minor defects
- Test it and informally tell the friend about bugs before logging them
Correct answer: Disclose the relationship to the project manager and ask for reassignment if objectivity may be compromised
Professional testers must disclose conflicts of interest and recuse themselves if objectivity cannot be maintained.
Question 12: Which FedRAMP testing requirement distinguishes cloud service providers seeking government contracts from standard commercial cloud vendors?
- Supporting single sign-on with Active Directory
- Providing on-premise deployment options
- Undergoing a third-party security assessment against NIST 800-53 controls (Correct answer)
- Having 99.99% uptime SLA
Correct answer: Undergoing a third-party security assessment against NIST 800-53 controls
FedRAMP requires cloud service providers to have their security controls independently assessed by an accredited Third Party Assessment Organization (3PAO).
Question 13: Which behavior BEST demonstrates a tester adhering to a 'quality mindset'?
- Proactively identifying risks and raising quality concerns early in the SDLC (Correct answer)
- Only testing features that developers request verification for
- Waiting until code is complete before thinking about testing
- Closing test cases quickly to meet quota
Correct answer: Proactively identifying risks and raising quality concerns early in the SDLC
A quality mindset means proactively thinking about quality and risk throughout the entire development lifecycle, not just at the end.
Question 14: What does the 'test oracle' concept refer to in software testing?
- A senior tester who reviews all test plans
- An automated tool that generates test cases
- A database of known software defects
- A mechanism for determining whether a test passed or failed (Correct answer)
Correct answer: A mechanism for determining whether a test passed or failed
A test oracle is any mechanism—specification, expected output, comparison system, or human judgment—used to determine whether the actual result matches the expected result.
Question 15: What is the consequence of non-compliance for Software Testing professionals?
- Only verbal warnings
- No significant consequences
- Just additional paperwork
- Potential fines, license revocation, legal liability, and reputational damage (Correct answer)
Correct answer: Potential fines, license revocation, legal liability, and reputational damage
This is fundamental to Software Testing practice. Potential fines, license revocation, legal liability, and reputational damage represents the professional standard for regulatory in the Software Testing certification framework.
Question 16: Which of the following BEST describes 'testability' of a software requirement?
- The requirement is specific enough that a pass/fail criterion can be clearly defined and tested (Correct answer)
- The requirement has been approved by the product owner
- The requirement has been converted into a user story format
- The requirement can be implemented in fewer than two weeks
Correct answer: The requirement is specific enough that a pass/fail criterion can be clearly defined and tested
A testable requirement has a clear, measurable pass/fail criterion that allows testers to objectively verify whether it has been met.
Question 17: Which document is typically required in FDA-regulated software projects to demonstrate that the testing approach is fit for purpose before testing begins?
- Test automation framework documentation
- Defect log
- Test summary report
- Validation protocol (Correct answer)
Correct answer: Validation protocol
A validation protocol pre-defines the testing approach, acceptance criteria, and responsibilities to be approved before execution begins.
Question 18: Which term describes a defect introduced while fixing another defect?
- Regression defect (Correct answer)
- Masked defect
- Secondary defect
- Latent defect
Correct answer: Regression defect
A regression defect (or regression) is introduced when a code change — including a bug fix — unintentionally breaks previously working functionality.
Question 19: Software testing should begin
- as soon as possible in the development life cycle (Correct answer)
- as soon as the code is written
- when the requirements have been formally documented
- during the design stage
Correct answer: as soon as possible in the development life cycle
Modern software development emphasizes 'shift-left' testing, meaning testing activities should commence as early as possible in the development life cycle. This includes reviewing requirements, designing test cases during the design phase, and performing static analysis on code. Early testing helps identify defects when they are cheaper and easier to fix, reducing overall project costs and improving software quality.
Question 20: The term "alpha testing" refers to
- the first testing that is performed.
- pre-release testing by end user representatives at the developer's site. (Correct answer)
- pre-release testing by end user representatives at their sites.
- post-release testing by end user representatives at the developer's site.
Correct answer: pre-release testing by end user representatives at the developer's site.
Alpha testing is a type of acceptance testing conducted internally by the development team or by a dedicated testing team, often with simulated or actual end-user representatives, at the developer's site. Its purpose is to identify as many defects as possible before releasing the software to external users for beta testing. It typically focuses on catching bugs and usability issues in a controlled environment.
Question 21: Defect density is calculated as:
- Defects found per tester
- Total defects divided by total test cases
- Total defects divided by the size of the software (e.g., per KLOC) (Correct answer)
- Defects per sprint divided by story points
Correct answer: Total defects divided by the size of the software (e.g., per KLOC)
Defect density measures the number of defects per unit of software size (typically per thousand lines of code), enabling quality comparisons across modules.
Question 22: What is 'shift-left testing' in the context of digital application development?
- Involving testers and writing tests earlier in the development lifecycle (Correct answer)
- Shifting the test team to a different department
- Moving all testing to the end of the project
- Running tests from left to right in a test matrix
Correct answer: Involving testers and writing tests earlier in the development lifecycle
Shift-left testing integrates quality activities earlier in the SDLC to catch defects sooner and reduce the cost of fixing them.
Question 23: A QA engineer wants to test a Progressive Web App (PWA) offline functionality. What aspect should they focus on?
- SSL certificate validity
- Service worker caching and offline data availability (Correct answer)
- Color contrast ratios
- Server-side rendering latency
Correct answer: Service worker caching and offline data availability
PWA offline support relies on service workers to cache assets and data, so testing should verify what content is available without a network connection.
Question 24: Which testing challenge is MOST unique to compliance testing compared to standard functional testing?
- Achieving high code coverage percentages
- Reducing the number of test cycles
- Providing legally defensible documentation that requirements were met (Correct answer)
- Finding defects before release
Correct answer: Providing legally defensible documentation that requirements were met
Compliance testing must produce auditable, legally defensible evidence that regulatory requirements were verified, not just confirm the software works.
Question 25: Which type of software review is the most formal and structured, with defined roles including a moderator, author, reviewers, and scribe?
- Technical review
- Inspection (Correct answer)
- Informal review
- Walkthrough
Correct answer: Inspection
Fagan inspections are the most formal review type with defined roles, entry/exit criteria, checklists, and metrics collection.
Question 26: A quality audit reveals that developers are skipping unit tests to meet sprint deadlines. The QA manager's BEST response is to:
- Recommend adding unit testing to the Definition of Done and escalate to management (Correct answer)
- Perform additional manual testing to compensate
- Accept the risk and document it in the test summary report
- Reduce the sprint scope to allow time for testing
Correct answer: Recommend adding unit testing to the Definition of Done and escalate to management
Embedding unit testing in the Definition of Done makes it a non-negotiable quality gate, and escalating ensures management enforces the standard consistently.
Question 27: What does defect 'priority' indicate?
- The testing phase when it was found
- How complex the defect is to reproduce
- The root cause of the defect
- How urgently the defect needs to be fixed relative to business needs (Correct answer)
Correct answer: How urgently the defect needs to be fixed relative to business needs
Priority reflects the business urgency for fixing a defect, which may differ from its technical severity.
Question 28: A mobile app is released and users report it crashes on older Android versions not tested by QA. What testing strategy was most neglected?
- Performance testing
- Security testing
- Usability testing
- Compatibility testing (Correct answer)
Correct answer: Compatibility testing
Compatibility testing verifies that software functions correctly across different devices, OS versions, and environments, which was insufficient here.
Question 29: Which metric best measures the completeness of automated test coverage?
- Number of test scripts
- Number of testers on the team
- Test execution speed
- Code coverage percentage (Correct answer)
Correct answer: Code coverage percentage
Code coverage percentage indicates how much of the source code is exercised by the automated test suite, highlighting untested areas.
Question 30: Which type of testing tool is Selenium primarily used for?
- Database testing
- Web UI automated functional testing (Correct answer)
- Performance testing
- Security vulnerability scanning
Correct answer: Web UI automated functional testing
Selenium is an open-source framework that automates web browser interactions for functional and regression testing of web applications.
Question 31: What is the first step when a tester discovers a defect?
- Close the related test case
- Log it in the defect tracking system with reproducible steps (Correct answer)
- Fix it immediately
- Inform the project manager verbally
Correct answer: Log it in the defect tracking system with reproducible steps
Defects must be formally logged with clear reproduction steps, severity, and environment details so developers can investigate and fix them.
Question 32: Which CMMI process area focuses on establishing and maintaining an understanding of requirements to minimize misinterpretation?
- Requirements Management (Correct answer)
- Requirements Development
- Validation
- Technical Solution
Correct answer: Requirements Management
Requirements Management ensures that requirements are understood, agreed upon, and changes are controlled throughout the project lifecycle.
Question 33: A test team is documenting their work on a nuclear plant control system under IEC 62645. What makes test documentation requirements here STRICTER than typical commercial software?
- All tests must be automated with zero manual testing
- Code coverage must reach exactly 100% statement coverage
- Documentation must support post-incident forensic analysis and regulatory inspections for the plant's operational lifetime (Correct answer)
- Tests must be written in a formal mathematical notation
Correct answer: Documentation must support post-incident forensic analysis and regulatory inspections for the plant's operational lifetime
Nuclear plant software documentation must withstand regulatory inspection and support incident investigation across decades of plant operation, far exceeding typical commercial retention needs.
Question 34: In a software testing experiment comparing two code coverage criteria, what is the 'dependent variable'?
- The number of testers assigned to each group
- The programming language used to write the software under test
- The coverage criterion chosen for each group
- The outcome being measured, such as defect detection rate or branch coverage achieved (Correct answer)
Correct answer: The outcome being measured, such as defect detection rate or branch coverage achieved
The dependent variable is what is measured as the outcome; the independent variable is the coverage criterion being manipulated.
Question 35: What does 'defect leakage' refer to?
- Defects introduced by fixing other defects
- Defects that escape testing and reach production (Correct answer)
- Defects that leak between test environments
- Defects in data security controls
Correct answer: Defects that escape testing and reach production
Defect leakage measures the number of defects found by end users in production that should have been caught during testing.
Question 36: What is a 'duplicate' defect status?
- A defect already reported by someone else in the system (Correct answer)
- A defect that occurs twice in the same test run
- A defect affecting two separate modules
- A defect reported in two different environments
Correct answer: A defect already reported by someone else in the system
A defect is marked 'Duplicate' when it has already been logged in the tracking system, and the new report is closed in favor of the original.
Question 37: Prioritizing tests ensures that
- You do more effective testing
- You shorten the time required for testing
- You find more faults
- You do the best testing in the time available (Correct answer)
Correct answer: You do the best testing in the time available
Prioritizing tests is crucial for optimizing testing efforts, especially under time constraints. It ensures that the most critical functionalities, highest-risk areas, or most frequently used features are tested first and most thoroughly. By focusing on high-priority tests, teams maximize the likelihood of finding significant defects and delivering the most valuable testing within the given schedule and resources.
Question 38: What is the PRIMARY purpose of a test summary report shared with stakeholders at project end?
- To list all tools used during testing
- To provide an objective overview of testing activities, coverage, results, and outstanding risks (Correct answer)
- To assign blame for unresolved defects
- To request additional testing budget for the next phase
Correct answer: To provide an objective overview of testing activities, coverage, results, and outstanding risks
The test summary report gives stakeholders a transparent view of quality status and remaining risks.
Question 39: When testing a cloud-based SaaS application, which concern is unique compared to testing on-premise software?
- Multi-tenancy data isolation (Correct answer)
- Code compilation errors
- Unit test coverage
- Functional correctness
Correct answer: Multi-tenancy data isolation
SaaS applications serve multiple customers on shared infrastructure, so verifying that one tenant cannot access another's data is critical.
Question 40: Which QA activity focuses on verifying that all identified defects have been corrected without introducing new issues?
- Regression testing
- Sanity testing
- Exploratory testing
- Confirmation testing (Correct answer)
Correct answer: Confirmation testing
Confirmation testing (also called re-testing) verifies that a specific defect has been fixed after a fix is applied.
ISTQB Certified Tester Foundation Level (CTFL)
The ISTQB Certified Tester Foundation Level (CTFL) certification validates core knowledge of software testing principles, methodologies, techniques, and best practices recognized globally across the software industry.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds