โ† All Software Testing Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Software Testing practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. Under CCPA (California Consumer Privacy Act), testing of a web application should verify which consumer-facing functionality?

    Answer: That consumers can opt out of the sale of their personal information

    CCPA requires businesses to provide a clear mechanism for California consumers to opt out of the sale of their personal information, which must be tested for correct functionality.

  2. In a regulated pharmaceutical environment following GAMP 5 guidelines, what category would fully custom-developed software fall under?

    Answer: Category 5

    GAMP 5 Category 5 covers custom applications developed to meet specific user requirements, requiring the highest level of validation effort.

  3. What does 'boundary value testing' help verify in a compliance context for financial software?

    Answer: That the system correctly handles regulatory thresholds such as transaction reporting limits

    In financial compliance, boundary value testing ensures systems correctly trigger regulatory actions (like suspicious activity reports) at mandated thresholds.

  4. Which FedRAMP testing requirement distinguishes cloud service providers seeking government contracts from standard commercial cloud vendors?

    Answer: Undergoing a third-party security assessment against NIST 800-53 controls

    FedRAMP requires cloud service providers to have their security controls independently assessed by an accredited Third Party Assessment Organization (3PAO).

  5. A test team is documenting their work on a nuclear plant control system under IEC 62645. What makes test documentation requirements here STRICTER than typical commercial software?

    Answer: Documentation must support post-incident forensic analysis and regulatory inspections for the plant's operational lifetime

    Nuclear plant software documentation must withstand regulatory inspection and support incident investigation across decades of plant operation, far exceeding typical commercial retention needs.

  6. In compliance testing, what is a 'test witness' and when are they typically required?

    Answer: An authorized independent person who observes and signs off on critical test execution to ensure integrity

    A test witness is an authorized observer (often a QA manager, client, or regulator representative) required in high-stakes compliance testing to attest that tests were executed as documented.

  7. When testing software for EU MDR (Medical Device Regulation) compliance, what must usability testing specifically demonstrate beyond basic UX feedback?

    Answer: That use errors and hazardous situations arising from the user interface have been identified and mitigated

    EU MDR usability testing (following IEC 62366) must identify how user interface design could lead to use errors that pose safety risks, not just assess satisfaction.