CTFL Sample Questions & Answers
Test analysis and design, with black-box and white-box techniques, takes the biggest slice, close to managing test activities like planning and risk, plus why testing matters and its guiding principles, lifecycle test levels and types, static reviews, and tool support.
Launch the full CTFL simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Managing the Test Activities · Test Control
A project is behind schedule, and management is pressuring the test team to sign off on a release. The test manager's dashboard shows that while 95% of planned test cases have been executed, the test coverage on the highest-risk modules is only at 60%. Several high-severity defects remain open. Which of the following is the MOST appropriate action for the test manager to take?
Show answer & explanation
Correct answer: A
The role of the test manager is not to unilaterally approve or block a release but to provide clear, data-driven information to stakeholders so they can make an informed business decision. The most professional and appropriate action is to communicate the exact testing status, including coverage of high-risk areas and the specific residual risks (open defects, untested areas). This allows stakeholders to formally accept the risk before proceeding.
- Question 2IntermediateSelect 3
Managing the Test Activities · Defect Management
A test analyst is writing a defect report for a crash that occurs when uploading a file. To ensure the developers can reproduce and fix the issue efficiently, which THREE of the following items are MOST essential to include in the defect report? (Select THREE).
Show answer & explanation
Correct answers: D, E, F
A good title (e.g., 'Crash on file upload with >10MB PNG file') immediately informs the developer of the problem's nature and context.
Clearly stating what happened (actual result: 'Application crashes') versus what should have happened (expected result: 'File uploads successfully and a confirmation message appears') defines the failure and removes ambiguity.
This is the most critical part of a defect report. Without clear, repeatable steps, the developer may be unable to find, diagnose, or fix the bug.
- Question 3Beginner
Static Testing · Static Testing Basics
A developer runs a static analysis tool (linter) on their source code before committing it to the repository. The tool reports a potential null pointer exception on a rarely used code path. This activity is an example of:
Show answer & explanation
Correct answer: A
Static testing involves examining work products (like source code) without executing them. Static analysis tools automate this process by checking the code against predefined rules and patterns to find potential defects, such as the null pointer exception mentioned. It is not dynamic testing because the code was not run.
- Question 4Beginner
Testing Throughout the Software Development Lifecycle · Confirmation Testing and Regression Testing
True or False: The primary purpose of confirmation testing (re-testing) is to ensure that a bug fix has not introduced new defects in other areas of the application.
Show answer & explanation
Correct answer: B
This statement describes regression testing. The primary purpose of confirmation testing is to verify that the original reported defect has been successfully fixed. Regression testing is the separate activity performed to check for unintended side effects (new defects) in unchanged parts of the software.
- Question 5Beginner
Managing the Test Activities · Risk Management
A project is developing a customer relationship management (CRM) system. The lead tester is creating the master test plan. Which of the following is an example of a PRODUCT risk, as opposed to a project risk?
Show answer & explanation
Correct answer: C
Product risks are related to the quality and characteristics of the software itself (what it does). A failure to secure data is a quality issue inherent to the product. Project risks are related to the management and execution of the project (how it's built), such as staff leaving, budget cuts, or schedule delays.
- Question 6Beginner
Fundamentals of Testing · Test Activities, Testware and Test Roles
During test analysis for an e-commerce application, a tester breaks down the requirement 'A user can pay with a valid credit card' into several specific, verifiable items such as 'Verify payment with a valid Visa card', 'Verify payment with a valid Mastercard', and 'Verify payment fails with an expired card'. What are these verifiable items called?
Show answer & explanation
Correct answer: A
A test condition is an item or event of a component or system that could be verified by one or more test cases. In the test analysis phase, high-level requirements are broken down into these more specific, testable conditions before detailed test cases (with steps and expected results) are designed.
- Question 7Intermediate
Test Analysis and Design · Experience-based Test Techniques
A software tester is assigned to a project late in the development lifecycle, just before the system testing phase. They notice the requirements are vague and there is very little documentation. Which test technique would be MOST effective in this situation to quickly gain an understanding of the application and identify potential defects?
Show answer & explanation
Correct answer: B
Exploratory testing is an experience-based technique where the tester simultaneously learns about the system, designs tests, and executes them. It is particularly powerful when documentation is poor or missing, as it relies on the tester's skill, curiosity, and critical thinking to uncover defects that formal, specification-based techniques might miss.
- Question 8Advanced
Static Testing · Feedback and Review Process
Case Study: HealthData Migration Project
A healthcare provider, "CareFirst Clinic," is migrating patient records from a 20-year-old legacy system to a new, modern Electronic Health Record (EHR) platform. The migration involves complex data transformation rules. The project follows a V-model development lifecycle. The business requirements for the new EHR platform have been signed off, and the high-level design is complete. The project is currently in the architectural design phase.
The test manager has identified a major product risk: "Incorrect mapping of patient allergy data from the legacy format to the new format could lead to severe patient safety incidents." The test team is composed of experienced testers with strong domain knowledge but limited experience with formal review processes. The test manager wants to ensure this specific risk is mitigated as early as possible.
Given the project's current phase and the nature of the risk, which activity should the test manager initiate immediately?
Show answer & explanation
Correct answer: B
According to the V-model and the principle of early testing, test activities should begin as soon as the corresponding development work product is available. The highest risk is in the data mapping logic, which is defined in design documents. Initiating a static testing activity, specifically a technical review of these documents, allows for the early detection of defects in the mapping rules before any code is written or data is migrated. This directly mitigates the identified patient safety risk at the earliest possible stage.
- Question 9Intermediate
Managing the Test Activities · Risk Management
A project team is using a risk-based testing strategy. The risk analysis has identified that the payment processing module has the highest level of product risk. According to risk-based testing principles, how should this influence the test effort?
Show answer & explanation
Correct answer: C
Risk-based testing uses product risk levels to guide test planning and execution. The highest-risk areas should receive the most intense testing (highest rigor) and should be tested as early as possible to find and fix critical defects sooner, thereby reducing the overall risk to the project.
- Question 10Intermediate
Fundamentals of Testing · Independence of Testing
In a software development project, testing is performed by developers on their own code (component testing), then by a dedicated test team (system testing), and finally by end-users (acceptance testing). What is the primary benefit of having these different levels of independence in testing?
Show answer & explanation
Correct answer: C
The main benefit of test independence is that different people find different bugs. Developers are good at finding low-level coding defects but may share the same assumptions they made when writing the code (cognitive bias). An independent test team will challenge those assumptions and focus on system-wide behavior. End-users will find defects related to real-world usability and workflow that technical teams might miss.
Ready for the real thing?
The full CTFL simulator has every exam-style question, timed mode, and instant scoring.