ISTQB Certified Tester Foundation Level (CTFL) — Questions and Answers
Question 1: A test team is documenting their work on a nuclear plant control system under IEC 62645. What makes test documentation requirements here STRICTER than typical commercial software?
- Code coverage must reach exactly 100% statement coverage
- Tests must be written in a formal mathematical notation
- All tests must be automated with zero manual testing
- Documentation must support post-incident forensic analysis and regulatory inspections for the plant's operational lifetime (Correct answer)
Correct answer: Documentation must support post-incident forensic analysis and regulatory inspections for the plant's operational lifetime
Nuclear plant software documentation must withstand regulatory inspection and support incident investigation across decades of plant operation, far exceeding typical commercial retention needs.
Question 2: Which tool is commonly used for root cause analysis in Software Testing quality management?
- Fishbone (Ishikawa) diagram to identify contributing factors systematically (Correct answer)
- Profit analysis
- Random sampling
- Customer surveys only
Correct answer: Fishbone (Ishikawa) diagram to identify contributing factors systematically
This is fundamental to Software Testing practice. Fishbone (Ishikawa) diagram to identify contributing factors systematically represents the professional standard for quality in the Software Testing certification framework.
Question 3: What is the significance of a code of conduct for Software Testing professionals?
- It limits professional freedom
- It establishes expected behaviors and ethical standards that protect the public and profession (Correct answer)
- It is merely symbolic
- It applies only to new practitioners
Correct answer: It establishes expected behaviors and ethical standards that protect the public and profession
This is fundamental to Software Testing practice. It establishes expected behaviors and ethical standards that protect the public and profession represents the professional standard for professional standards in the Software Testing certification framework.
Question 4: Which testing approach tests the interaction between integrated components or systems?
- Integration testing (Correct answer)
- Exploratory testing
- Unit testing
- System testing
Correct answer: Integration testing
Integration testing verifies that different modules or services work correctly together when combined.
Question 5: What does 'blue-green deployment' allow QA teams to do more safely?
- Deploy twice as fast by skipping staging
- Assign blue tickets to bugs and green tickets to enhancements
- Color-code test suites by priority
- Run tests in parallel on two identical environments and switch traffic only after validation (Correct answer)
Correct answer: Run tests in parallel on two identical environments and switch traffic only after validation
Blue-green deployment keeps two identical environments; the new release is validated on the inactive environment before traffic is switched, reducing rollout risk.
Question 6: In a CI/CD pipeline, at which stage are automated functional tests most commonly executed?
- Before source code is committed
- After code is merged and the build artifact is created (Correct answer)
- Only in the production environment
- Exclusively during sprint planning
Correct answer: After code is merged and the build artifact is created
Automated functional tests run as part of the CI pipeline after a build is compiled, providing fast feedback before deployment to higher environments.
Question 7: How do Software Testing professionals ensure compliance in daily practice?
- By integrating compliance requirements into standard operating procedures and regular audits (Correct answer)
- By memorizing all regulations
- By hiring a compliance officer
- Compliance is checked only annually
Correct answer: By integrating compliance requirements into standard operating procedures and regular audits
This is fundamental to Software Testing practice. By integrating compliance requirements into standard operating procedures and regular audits represents the professional standard for regulatory in the Software Testing certification framework.
Question 8: Which metric measures the elapsed time from when a user sends a request to when they receive a complete response?
- Concurrency
- Error rate
- Response time (Correct answer)
- Throughput
Correct answer: Response time
Response time is the interval between a user submitting a request and receiving the full response, making it a key user-experience metric.
Question 9: A tester finds that a login form accepts a blank username. The correct behavior should be to show a validation error. This defect is best classified as:
- Usability defect
- Performance defect
- Functional defect (Correct answer)
- Security vulnerability only
Correct answer: Functional defect
A functional defect is a deviation from the specified functional behavior, such as failing to enforce required field validation on login.
Question 10: How do Software Testing professionals maintain digital competency?
- Through ongoing training, practice with new tools, and staying current with technological advances (Correct answer)
- Skills from initial training are sufficient
- Digital skills are not required
- By hiring IT support for all tasks
Correct answer: Through ongoing training, practice with new tools, and staying current with technological advances
This is fundamental to Software Testing practice. Through ongoing training, practice with new tools, and staying current with technological advances represents the professional standard for technology in the Software Testing certification framework.
Question 11: Why is documentation important in Software Testing risk management?
- It creates an audit trail, supports decision-making, and demonstrates due diligence (Correct answer)
- It slows down operations
- It is optional paperwork
- It only benefits legal teams
Correct answer: It creates an audit trail, supports decision-making, and demonstrates due diligence
This is fundamental to Software Testing practice. It creates an audit trail, supports decision-making, and demonstrates due diligence represents the professional standard for risk management in the Software Testing certification framework.
Question 12: What is a 'latent defect' in software?
- A defect introduced by the latest code change
- A defect that exists in the software but has not yet been discovered (Correct answer)
- A defect in the test environment configuration
- A defect that only appears under load
Correct answer: A defect that exists in the software but has not yet been discovered
A latent defect is one that already exists in the software but remains undetected until specific conditions trigger its manifestation.
Question 13: A software team adopts pair reviews where two developers inspect code together in real time. This practice is best described as:
- Walkthrough
- Over-the-shoulder review (Correct answer)
- Formal inspection
- Pair programming inspection
Correct answer: Over-the-shoulder review
An over-the-shoulder review occurs when one developer watches another review or write code and provides real-time feedback.
Question 14: What does defect 'priority' indicate?
- How complex the defect is to reproduce
- The testing phase when it was found
- How urgently the defect needs to be fixed relative to business needs (Correct answer)
- The root cause of the defect
Correct answer: How urgently the defect needs to be fixed relative to business needs
Priority reflects the business urgency for fixing a defect, which may differ from its technical severity.
Question 15: Which type of software review is the most formal and structured, with defined roles including a moderator, author, reviewers, and scribe?
- Informal review
- Inspection (Correct answer)
- Walkthrough
- Technical review
Correct answer: Inspection
Fagan inspections are the most formal review type with defined roles, entry/exit criteria, checklists, and metrics collection.
Question 16: What is equivalence partitioning in software testing?
- Splitting the codebase into modules
- Grouping inputs that should behave the same way (Correct answer)
- Allocating testers to different features
- Dividing test cases by priority
Correct answer: Grouping inputs that should behave the same way
Equivalence partitioning divides input data into groups (partitions) where all values in a partition are expected to be processed identically.
Question 17: What is the main challenge of record-and-playback test automation?
- Scripts are brittle and break when the UI changes (Correct answer)
- It requires advanced programming skills
- It only works on mobile devices
- It cannot test web applications
Correct answer: Scripts are brittle and break when the UI changes
Recorded scripts are tightly coupled to UI element positions and properties, so minor UI changes frequently break them.
Question 18: In SOC 2 (Service Organization Control 2) compliance, which testing validates the 'Availability' trust service criterion?
- Testing that systems meet agreed-upon uptime commitments and recovery objectives (Correct answer)
- Verifying that encryption keys are rotated quarterly
- Checking that software licenses are current
- Confirming that all users have multi-factor authentication
Correct answer: Testing that systems meet agreed-upon uptime commitments and recovery objectives
SOC 2 Availability testing verifies that systems are operational and accessible as committed, typically through uptime measurement and disaster recovery testing.
Question 19: A tester is embedded in a Scrum team and has identified a pattern of recurring defects in a specific module. How should this be communicated?
- File individual defects without drawing attention to the pattern
- Present the pattern with data (defect count, trend, root cause hypothesis) at the retrospective or with the team lead (Correct answer)
- Mention it casually to the developer nearest the module
- Wait until the project is complete and include it in the final report
Correct answer: Present the pattern with data (defect count, trend, root cause hypothesis) at the retrospective or with the team lead
Data-driven pattern reporting at the right forum drives systemic fixes rather than one-off patches.
Question 20: Which metric best measures the completeness of automated test coverage?
- Number of test scripts
- Test execution speed
- Number of testers on the team
- Code coverage percentage (Correct answer)
Correct answer: Code coverage percentage
Code coverage percentage indicates how much of the source code is exercised by the automated test suite, highlighting untested areas.
Question 21: What is the first step when a tester discovers a defect?
- Inform the project manager verbally
- Close the related test case
- Log it in the defect tracking system with reproducible steps (Correct answer)
- Fix it immediately
Correct answer: Log it in the defect tracking system with reproducible steps
Defects must be formally logged with clear reproduction steps, severity, and environment details so developers can investigate and fix them.
Question 22: A QA team discovers that running the same set of regression tests over many cycles no longer finds new defects. This phenomenon is called:
- Confirmation bias
- Defect clustering
- Test saturation
- The pesticide paradox (Correct answer)
Correct answer: The pesticide paradox
The pesticide paradox describes how repeatedly running the same tests eventually stops finding new bugs because the software adapts and test cases become ineffective over time.
Question 23: Which standard provides guidelines specifically for software process capability determination?
- CMMI
- ISO 9001
- ISO/IEC 15504 (SPICE) (Correct answer)
- IEEE 829
Correct answer: ISO/IEC 15504 (SPICE)
ISO/IEC 15504, known as SPICE (Software Process Improvement and Capability dEtermination), defines a framework for assessing software process capability.
Question 24: What distinguishes a 'mapping study' from a full 'systematic literature review' in software testing research?
- A mapping study provides a broad overview of research trends; an SLR provides in-depth synthesis of evidence (Correct answer)
- A mapping study is more rigorous because it uses stricter inclusion criteria
- An SLR covers only published conference papers; a mapping study includes gray literature
- A mapping study always includes meta-analysis; an SLR does not
Correct answer: A mapping study provides a broad overview of research trends; an SLR provides in-depth synthesis of evidence
Mapping studies classify and visualize the landscape of research on a topic, while SLRs deeply synthesize evidence to answer specific research questions.
Question 25: When testing software for EU MDR (Medical Device Regulation) compliance, what must usability testing specifically demonstrate beyond basic UX feedback?
- That the UI follows Google Material Design guidelines
- That use errors and hazardous situations arising from the user interface have been identified and mitigated (Correct answer)
- That the software loads in under 3 seconds on all devices
- That the software passes all automated accessibility checks
Correct answer: That use errors and hazardous situations arising from the user interface have been identified and mitigated
EU MDR usability testing (following IEC 62366) must identify how user interface design could lead to use errors that pose safety risks, not just assess satisfaction.
Question 26: A quality audit reveals that developers are skipping unit tests to meet sprint deadlines. The QA manager's BEST response is to:
- Reduce the sprint scope to allow time for testing
- Recommend adding unit testing to the Definition of Done and escalate to management (Correct answer)
- Perform additional manual testing to compensate
- Accept the risk and document it in the test summary report
Correct answer: Recommend adding unit testing to the Definition of Done and escalate to management
Embedding unit testing in the Definition of Done makes it a non-negotiable quality gate, and escalating ensures management enforces the standard consistently.
Question 27: Which statement correctly describes the difference between risk avoidance and risk reduction?
- Avoidance transfers the risk; reduction accepts it
- Avoidance and reduction are interchangeable terms
- Avoidance lowers probability; reduction lowers impact only
- Avoidance eliminates the risk entirely; reduction lowers its probability or impact (Correct answer)
Correct answer: Avoidance eliminates the risk entirely; reduction lowers its probability or impact
Risk avoidance removes the cause of the risk completely (e.g., dropping a feature), while risk reduction takes actions that make the risk less likely or less harmful.
Question 28: Which compliance standard specifically governs the testing of software used in payment card processing systems?
- PCI DSS (Correct answer)
- HIPAA
- SOX
- GDPR
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) sets requirements for all systems that store, process, or transmit cardholder data.
Question 29: What is a 'showstopper' defect?
- A defect found in the first test run
- A defect that occurs only in the UI
- A minor cosmetic issue
- A critical defect that halts further testing or release (Correct answer)
Correct answer: A critical defect that halts further testing or release
A showstopper is a severe defect that blocks critical functionality, making it impossible to continue testing or release the software.
Question 30: What is the value of written documentation in Software Testing professional communication?
- It is optional
- It replaces verbal communication
- It is only for formal occasions
- It creates permanent records, ensures clarity, and provides legal protection (Correct answer)
Correct answer: It creates permanent records, ensures clarity, and provides legal protection
This is fundamental to Software Testing practice. It creates permanent records, ensures clarity, and provides legal protection represents the professional standard for communication in the Software Testing certification framework.
Question 31: What is 'risk velocity' in software risk management?
- The number of risks identified per sprint
- How quickly a risk can escalate from low to critical if not addressed (Correct answer)
- The speed at which test cases are executed
- The rate at which defects are being found during testing
Correct answer: How quickly a risk can escalate from low to critical if not addressed
Risk velocity measures how fast a risk can worsen or materialize, helping teams prioritize risks that can rapidly become severe.
Question 32: Under GDPR, which testing practice helps verify that personal data is not retained longer than necessary?
- Data retention compliance testing (Correct answer)
- Smoke testing
- Load testing
- Alpha testing
Correct answer: Data retention compliance testing
Data retention compliance testing verifies that systems automatically delete or anonymize personal data after the defined retention period expires.
Question 33: A meta-analysis of unit testing studies reports a 'weighted mean effect size.' Why is weighting applied?
- To normalize defect counts across projects with different programming languages
- To adjust for inflation in lines-of-code counts over different publication years
- To penalize studies that did not use random assignment
- To give larger or more precise studies more influence on the combined estimate (Correct answer)
Correct answer: To give larger or more precise studies more influence on the combined estimate
Weighting ensures that higher-quality or larger studies contribute more to the pooled effect size estimate than small, imprecise studies.
Question 34: A QA team is testing an AI-powered recommendation engine. What is a key challenge unique to this type of testing?
- Verifying non-deterministic outputs and model accuracy rather than fixed expected values (Correct answer)
- Writing Selenium scripts for the UI
- Configuring the CI pipeline
- Setting up a test database
Correct answer: Verifying non-deterministic outputs and model accuracy rather than fixed expected values
AI models can produce variable outputs, so testing must focus on statistical accuracy metrics and boundary conditions rather than exact value matching.
Question 35: Which quality assurance technique involves executing a program with the intent of finding errors, without reference to the internal structure?
- Code inspection
- Black-box testing (Correct answer)
- Static analysis
- White-box testing
Correct answer: Black-box testing
Black-box testing validates software behavior based solely on inputs and expected outputs without knowledge of internal implementation.
Question 36: A senior stakeholder asks for a 'quick gut check' on whether the system is ready to ship. What should the QA lead base their answer on?
- The development team's confidence level
- The number of days remaining before the deadline
- Objective data: test execution rates, open defect counts by severity, and risk coverage metrics (Correct answer)
- Personal intuition based on experience
Correct answer: Objective data: test execution rates, open defect counts by severity, and risk coverage metrics
Quality assessments must be grounded in measurable data to be credible and defensible.
Question 37: A defect marked as 'Deferred' means:
- The defect is invalid
- The defect cannot be reproduced
- The defect will not be fixed in the current release but may be addressed later (Correct answer)
- The defect has been fixed
Correct answer: The defect will not be fixed in the current release but may be addressed later
Deferred defects are acknowledged as real but intentionally postponed to a future release, often due to low priority or resource constraints.
Question 38: Defect density is calculated as:
- Defects found per tester
- Defects per sprint divided by story points
- Total defects divided by the size of the software (e.g., per KLOC) (Correct answer)
- Total defects divided by total test cases
Correct answer: Total defects divided by the size of the software (e.g., per KLOC)
Defect density measures the number of defects per unit of software size (typically per thousand lines of code), enabling quality comparisons across modules.
Question 39: What is the 'pesticide paradox' in software testing?
- Testing too thoroughly kills developer motivation
- Using too many testing tools causes diminishing returns
- Repeatedly running the same tests stops finding new defects over time (Correct answer)
- Automated tests eventually poison the test environment
Correct answer: Repeatedly running the same tests stops finding new defects over time
The pesticide paradox states that if the same tests are repeated over and over, they eventually cease to find new bugs, just as pests become resistant to pesticides.
Question 40: Which qualitative risk analysis output is used to rank risks so teams can decide which to address first?
- Decision tree analysis
- Risk probability-impact matrix (Correct answer)
- Monte Carlo simulation results
- Expected monetary value (EMV)
Correct answer: Risk probability-impact matrix
The probability-impact matrix plots risks on a grid and produces a ranked priority list without requiring numerical monetary data.
ISTQB Certified Tester Foundation Level (CTFL)
The ISTQB Certified Tester Foundation Level (CTFL) certification validates core knowledge of software testing principles, methodologies, techniques, and best practices recognized globally across the software industry.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds