ISTQB · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
Refer to the exhibit. Which testing activity is most appropriate to determine the root cause of these cascading failures?
Test execution.
Debugging.
Debugging is specifically focused on identifying the underlying cause of a failure. By analyzing the time-stamped logs, developers and testers can trace the sequence of events leading to the crash. This process is distinct from testing, as it involves isolating the faulty code responsible for the observed system errors.
Test monitoring.
Regression testing.
A tester is working on a project where the requirements are vague and constantly changing. Which testing mindset is most beneficial here?
Rigidly following the initial test plan.
Waiting for final requirements before starting testing.
Maintaining a curious and collaborative mindset.
A curious and collaborative mindset allows testers to engage with developers and stakeholders to clarify ambiguity. This enables them to provide early feedback and adapt test cases as features evolve. This flexibility is vital in agile or volatile environments where the product scope is frequently adjusted by the business.
Focusing only on automated test scripts.
Which of the following describes the 'pesticide paradox' in software testing?
Testers find fewer bugs as they spend more time on a module.
Repeating the same test cases will eventually stop finding new defects.
The pesticide paradox states that if the same tests are executed repeatedly, they will stop finding new defects. To find more bugs, existing tests need to be updated, and new, different tests need to be added to the suite to maintain test effectiveness throughout the software development lifecycle.
Automated tests are less effective than manual tests.
Testing becomes more expensive over time.
A software project has a high cost of failure. Which testing approach should the test manager prioritize to minimize risk?
Exhaustive testing of all features.
Risk-based testing.
Risk-based testing uses the project's risk profile to prioritize test cases. By focusing testing on high-risk areas—those where failure is likely or where the impact is severe—the team can maximize the effectiveness of their testing effort, providing the greatest value and protection for the business and the end-users.
Testing only the UI components.
Automated regression testing only.
What is the primary difference between verification and validation in the context of testing?
Verification is for developers, validation is for testers.
Verification checks specifications; validation checks user needs.
Verification is concerned with confirming that the product matches the requirements and design specifications. Validation is concerned with ensuring that the product satisfies the user's requirements and needs in the real-world operational environment. Both processes are crucial for confirming that the final software is both correct and useful.
Validation is done early; verification is done late.
Verification is testing; validation is debugging.
Which of the following is a primary objective of testing?
To guarantee that the software is bug-free.
To find as many bugs as possible.
To provide information about the system's quality.
Testing provides data and evidence regarding how well the software performs against expectations. This information enables stakeholders to make informed decisions about whether the system is ready for release, what risks remain, and where further development or maintenance effort should be directed to ensure long-term stability and success.
To automate as many test cases as possible.
Want more Fundamentals of Testing practice?
Practice this domainA software company is adopting static testing to reduce defect leakage. Which of the following scenarios best demonstrates the primary benefit of static testing over dynamic testing?
The testing team executes a test script to identify a logic error in the billing module.
Developers perform unit tests to verify that the API endpoints handle null inputs correctly.
A peer review of a technical specification document reveals an ambiguity that would lead to incorrect business logic.
This scenario highlights the core benefit of static testing: identifying defects early in the development lifecycle before code is written. By catching the ambiguity in the design phase, the team avoids the high cost of rework that would occur if the defect were discovered during dynamic testing.
A performance tool monitors system latency to ensure compliance with non-functional requirements.
During a formal review process, which role is primarily responsible for documenting the defects found during the review meeting?
The Moderator
The Author
The Scribe
The scribe is explicitly tasked with documenting all findings, defects, and suggestions identified during the meeting. This ensures a consistent record of the review outcomes, which is vital for the author to understand the necessary improvements required to meet the quality standards defined for the work product.
The Reviewer
Which TWO of the following statements accurately describe the characteristics of a formal review process?
Formal reviews must always include the participation of a test manager.
Formal reviews follow a documented process with defined roles and entry/exit criteria.
A hallmark of formal reviews is the presence of a structured process, including specific roles like moderator and scribe. Entry and exit criteria ensure that the review is conducted efficiently and that the results meet the project's quality requirements before moving to the next stage.
Formal reviews always require the use of automated static analysis tools.
Formal reviews result in a documented report of the findings and potential improvements.
Documentation is essential in a formal review. The scribe records all identified defects and suggestions, which are then compiled into a formal report. This documentation provides a clear audit trail and ensures the author has the necessary information to perform effective rework on the product.
Formal reviews are generally faster and cheaper than informal reviews.
Which of the following best describes the purpose of 'Entry Criteria' in a formal review process?
To determine which reviewers are qualified to participate in the session.
To provide a checklist that the author can use to fix defects found during the review.
To ensure that the work product is in a suitable state to be reviewed effectively.
Entry criteria ensure that the document has reached a sufficient level of quality or completeness to warrant a formal review. This prevents reviewers from spending time on trivial issues or obvious errors, allowing them to focus on complex logic, requirements, or design issues during the meeting.
To track the number of defects found by each individual reviewer during the meeting.
Why is it important to include the author in the review meeting?
To allow the author to defend their design decisions against reviewer criticisms.
To provide explanations that help reviewers understand the logic and intent of the product.
The author can clarify complex areas, reducing the time reviewers spend guessing the intent of the documentation. This leads to more efficient defect detection and prevents reviewers from logging false positives based on a misunderstanding of the original design goals or business requirements.
To assign blame to the author for any defects discovered during the meeting.
To ensure the author can rewrite the code or document during the meeting.
Which of the following is an example of an 'informal' review?
A structured inspection with a designated moderator and scribe.
A technical review conducted by a team with a predefined checklist.
A developer asking a colleague to look over their code for simple errors.
This is the classic example of an informal review. It is quick, involves no formal documentation, lacks defined roles like moderator or scribe, and is performed as an ad-hoc collaboration between peers, which is perfectly suited for small or low-risk development tasks.
A formal walkthrough where the author explains the design to a group.
Want more Static Testing practice?
Practice this domainA test manager is evaluating the introduction of test execution tools. Which scenario best describes a situation where a test execution tool is most likely to provide high return on investment?
The project involves highly volatile requirements with frequent UI changes every iteration.
The project is a small, one-time development effort with a very short timeline.
The project requires frequent, repetitive regression testing of a stable core product.
Stable core products that undergo frequent regression testing are ideal candidates for automation. Automation tools excel at executing large, repetitive suites quickly and accurately, minimizing the risk of human error. This frees up the human testers to perform complex exploratory testing, which adds higher value to the project's quality lifecycle.
The team lacks the necessary technical skills and has no budget for staff training.
Which TWO of the following statements regarding the selection and implementation of test tools are correct?
The tool should be selected primarily based on the lowest purchase cost to maximize budget.
A pilot project should be conducted to evaluate the tool's effectiveness in the real environment.
A pilot project is essential to validate that the tool works within the specific technical infrastructure and development process of the organization. It identifies potential integration issues, training needs, and procedural gaps before a full-scale deployment, significantly reducing the risk of a costly failed investment in a complex test automation suite.
Tool implementation should always involve changing the test process to match the tool's defaults.
The tool must be integrated with other parts of the development and test environment.
Seamless integration with existing tools, such as defect management systems, version control, and continuous integration pipelines, is vital for success. Isolated tools create manual data silos, hindering the flow of information and reducing the overall efficiency of the development cycle. Interoperability ensures that testing is truly part of the integrated delivery process.
Training is unnecessary if the tool vendor provides a comprehensive user manual.
Which category of test tools is primarily used to generate test data to be used by the application under test?
Test execution tools.
Test design tools.
Test data preparation tools.
These tools specifically automate the generation, extraction, and masking of data. They are crucial for ensuring that testers have the necessary environment state to execute tests effectively without manual intervention, which significantly speeds up the test preparation phase and helps maintain consistency across various testing cycles and environments.
Test management tools.
When considering the 'Test-first' approach to automation, which risk is most effectively mitigated by using static analysis tools?
Identifying performance bottlenecks during high-load scenarios.
Ensuring that the code adheres to predefined coding standards and style guides.
Static analysis tools are designed specifically to scan code against defined rulesets, including style guides and coding standards. This ensures consistency and quality throughout the codebase, making it easier for team members to read, maintain, and refactor code, which is an essential prerequisite for efficient and successful test-first automation efforts.
Detecting missing functional requirements in the user documentation.
Determining if the test suite has full branch coverage of the application.
Which THREE of the following are primary benefits of using a Test Management Tool in a large-scale project?
Automatic generation of unit tests based on code changes.
Providing centralized storage for test cases, scripts, and results.
Centralization is a key benefit, as it allows all stakeholders to access a single source of truth. This prevents version control conflicts and ensures that everyone is working with the latest test documentation, which is vital for consistency and accurate reporting in large teams distributed across different geographical locations.
Enabling traceability between requirements, test cases, and defects.
Traceability is crucial for impact analysis and coverage reporting. These tools map each requirement to the corresponding tests and identified defects, ensuring that no requirement is overlooked and that all reported issues can be linked back to the functional specification, which is essential for project governance and compliance audits.
Facilitating performance testing by simulating thousands of concurrent users.
Supporting reporting and metrics tracking for project progress.
Management tools offer real-time dashboards and reporting features that track test execution status, pass/fail rates, and defect trends. This quantitative data allows managers to assess the quality of the software and make informed decisions about release readiness, which is indispensable for managing large-scale projects with complex release schedules.
Which type of tool would best assist a tester in checking for memory leaks and resource usage during the execution of a software application?
Configuration management tool.
Static analysis tool.
Dynamic analysis tool.
Dynamic analysis tools monitor an application's behavior during execution. They are explicitly designed to track memory usage, identify leaks, and detect other runtime problems by observing the system state in real-time. This provides the insights necessary to optimize application performance and fix stability issues that static inspection would surely miss.
Test design tool.
Want more Test Tools practice?
Practice this domainRefer to the exhibit. A tester reviews this configuration file during the static testing of a test environment setup. What is the primary risk of this configuration in a formal testing phase?
The log level set to debug will cause an overflow error in the production database.
The exponential retry policy will increase the latency of the system during stress testing.
The disabled strict mode may allow invalid data to be processed, masking bugs.
Disabling strict mode allows the system to ignore data validation errors or schema violations. This masks defects that would trigger critical errors in a production environment where strict mode is enabled. Static testing of configuration files is essential to ensure the environment supports valid test execution and defect detection.
The environment tag set to 'dev' indicates that the deployment is insecure by design.
Which of the following activities best demonstrates the ISTQB principle of 'Testing provides early feedback'?
Executing automated regression tests at the end of each daily build.
Reviewing user stories and acceptance criteria during the sprint planning session.
Reviewing requirements during planning is a classic example of static testing. It provides immediate feedback to the product team, allowing them to clarify requirements, identify missing test conditions, and ensure the criteria are measurable. This activity prevents defects from being injected into the development process later on.
Conducting a performance test on the integrated system before the final release.
Reporting defects found during the User Acceptance Testing (UAT) phase.
Which TWO of the following statements accurately describe the role of testers in a modern SDLC?
Testers are solely responsible for all quality activities within the project.
Testers contribute by helping to define the acceptance criteria for user stories.
Testers help refine requirements by ensuring acceptance criteria are clear, measurable, and testable. By participating early, they identify edge cases and potential ambiguities, ensuring that the team understands exactly what needs to be built and verified, which significantly reduces the risk of misunderstood requirements and downstream defects.
Testers should focus exclusively on dynamic testing to prove the system works.
Testers facilitate the communication between technical and business stakeholders.
Testers often act as a bridge between technical teams and business stakeholders. By translating technical constraints into business risks and business requirements into test scenarios, they ensure that the final product meets the users' actual needs. This role is crucial for alignment and delivering high-value, quality software products.
Testers should avoid participating in code reviews to remain unbiased.
Which approach is most appropriate for maintaining quality when a project uses a DevOps culture with continuous deployment?
Manual exploratory testing of every build before it is moved to production.
Automated regression tests integrated into the pipeline combined with production monitoring.
Automated pipelines provide rapid verification of code changes, while production monitoring acts as a safety net. This dual approach ensures that defects are caught early in the development cycle and that any issues escaping to production are identified and addressed immediately, supporting a stable, high-speed release process.
Performing formal, document-heavy system testing cycles after every code merge.
Requiring a separate QA phase where developers are not involved in testing.
Which THREE of the following are benefits of static testing early in the SDLC?
Reduced cost of quality by finding defects before they are implemented in code.
Identifying defects in requirements or design is significantly cheaper than fixing them once they have been implemented. By catching errors during static testing, the team avoids the downstream costs associated with debugging, code rework, re-testing, and potential project delays, leading to a much more cost-effective development process.
Elimination of the need for any dynamic testing in the later stages.
Early identification of missing or ambiguous requirements.
Reviewing requirements early highlights gaps, contradictions, and ambiguities. This gives stakeholders and developers time to align their understanding before construction begins. Preventing these issues at the start is crucial, as requirements errors are the leading cause of project failure and significant rework in complex software development projects.
Increased understanding of the system by testers, leading to better test design.
Participating in reviews allows testers to gain deep insights into the intended system functionality. This knowledge enables the creation of more accurate and comprehensive test cases. Understanding the design early allows testers to plan edge cases and scenarios that might have been overlooked if they started testing later.
Automated code coverage analysis of the requirement document.
Refer to the exhibit. A tester sees this error during load testing. Based on the principle of 'Testing throughout the SDLC', what should be the immediate recommendation?
Ignore the error as it only occurs under high load, which is not the primary focus.
Increase the number of threads in the API gateway to mask the timeout.
Conduct a root cause analysis on the connection pool configuration and design.
Root cause analysis addresses the source of the timeout. By examining the connection pool, the team can determine if it is a configuration issue or a design flaw, such as failing to close connections properly. This systematic approach ensures long-term stability and aligns with the professional testing responsibility.
Immediately roll back the last code deployment to the production environment.
Want more Testing Throughout the SDLC practice?
Practice this domainA project manager is analyzing test progress during a sprint. The team has completed 60% of planned test cases, but 40% of those executed failed due to a critical environment issue. Which test management action is most appropriate?
Increase the number of testers to execute remaining cases faster.
Prioritize and resolve the environment issue before resuming test execution.
Addressing the environmental bottleneck is critical because high failure rates due to infrastructure prevent the team from verifying actual product functionality. By stabilizing the environment first, the test manager ensures that subsequent test executions yield valid, reliable results, preventing further waste of time and resources on false-positive defect reports.
Report the 60% completion rate to stakeholders to indicate success.
Stop testing immediately and declare the sprint a failure.
Which TWO of the following tasks are primary responsibilities of a test manager in a formal testing organization?
Writing low-level unit test cases for developer code review.
Defining the test strategy and scope for the project.
Defining the test strategy and scope is a core duty of the test manager. This ensures that the testing effort is focused on the most critical areas, providing a clear roadmap for the test team and ensuring that stakeholders understand what will be tested and what remains out of scope.
Executing manual regression tests during the final release phase.
Monitoring and controlling the test project against the test plan.
Monitoring and controlling involves tracking progress against the plan and taking corrective actions when deviations occur. This ensures the project remains on schedule and within budget, allowing the manager to adjust plans as needed to accommodate changes in project timelines or identified risks during the testing life cycle.
Configuring the continuous integration build server hardware.
Which document is primarily used by a test manager to outline the scope, objectives, and test schedule for a project?
Test Summary Report.
Test Plan.
The Test Plan is the foundational document that defines the scope, approach, resources, and schedule for the intended test activities. It acts as the primary communication tool for the test manager to coordinate the testing effort and align the expectations of various project stakeholders regarding the quality assurance process.
Test Case Specification.
Defect Report.
Which THREE factors should a test manager consider when estimating the effort required for a new testing project?
The complexity of the system under test.
System complexity directly impacts the effort needed to design and execute effective test cases. More complex systems require more time for test analysis, test design, and debugging, making it a primary factor in any realistic estimation process for a professional test management strategy.
The test team's experience and skill level.
The experience of the testers significantly affects productivity. A team with deeper domain knowledge or stronger automation skills will complete tasks faster than a novice team. Ignoring these capabilities leads to inaccurate schedules that can cause projects to miss deadlines or compromise on testing depth.
The salary of the individual test team members.
Availability of test environments and tools.
Test environments and tools are essential for execution. If these are unavailable or unstable, the effort will increase significantly due to delays and rework. Considering these constraints during the planning phase is vital for creating an achievable schedule and setting proper stakeholder expectations regarding the project timeline.
The branding colors and company logo requirements.
During project monitoring, the test manager realizes the team is falling behind the schedule due to an unexpectedly high number of defects. What is the most effective management response?
Demand the team work unpaid overtime to complete the original plan.
Reduce the scope of testing by focusing only on high-risk areas.
Reducing scope through risk-based prioritization is a standard management technique when schedules are compressed. By focusing on critical functionality, the test manager ensures that the most impactful risks are mitigated, maximizing the value of the remaining testing time and ensuring the project delivers a stable product to the customer.
Ignore the defects and continue with the original testing sequence.
Replace the test team with more experienced external consultants.
Why is it important for a test manager to implement a test-monitoring process throughout the software lifecycle?
To ensure that all testers are working at the same speed.
To identify deviations from the plan and take corrective action.
The core purpose of monitoring is to detect discrepancies between planned and actual progress. Once identified, the test manager can take corrective actions—such as reallocating resources or adjusting the test scope—to keep the project on track and minimize the impact of unforeseen issues on the final release schedule.
To justify the need for higher salaries for the team.
To fulfill requirements for legal compliance audits.
Want more Managing the Test Activities practice?
Practice this domainRefer to the exhibit. A software testing team is designing test cases based on a decision table derived from the provided JSON business rule policy. How should the tester handle the 'coupon_valid' condition when designing tests for 'is_member = true' and 'cart_total > 100.00' if the rule engine ignores coupons entirely under these specific criteria?
Create two separate test cases: one where coupon_valid is true and one where coupon_valid is false.
Design a single test case using a 'don't care' notation for coupon_valid since its state does not alter the outcome.
When the rule engine ignores coupons for these criteria, coupon_valid cannot affect the outcome, so its state is irrelevant. Don't-care notation collapses the two otherwise-identical rules into one test case, avoiding redundant coverage while preserving decision-table completeness.
Omit the cart_total variable from the test design entirely because the membership status takes precedence.
Automatically fail the test case because the JSON policy contains a conflicting boolean value for coupons.
According to the ISTQB CTFL v4.0 syllabus, which TWO of the following statements are characteristic of black-box test techniques? (Select TWO)
Test cases are derived from the internal code structure, architecture, or detailed design of the software component.
Test cases can be designed before the software is implemented, supporting early test analysis and design.
Specification-based techniques rely on functional requirements and user stories, which enables test analysts to design comprehensive test cases long before coding begins. This early involvement helps uncover ambiguities and defects in the requirements documentation.
The primary measure of test thoroughness is code statement or decision coverage achieved during execution.
Test conditions and test cases are based on formal or informal specifications of the component or system.
Black-box test design is fundamentally rooted in analyzing functional and non-functional specifications, user requirements, and business rules. This ensures that the developed software aligns perfectly with stakeholder expectations and contractual agreements.
Testers must have programming skills and access to the source code repository to successfully execute the technique.
During test design for a banking application, you identify that interest rates are applied based on customer tier (Bronze, Silver, Gold) and account balance ($0-$1000, $1001-$5000, $5000+). Which technique is most effective for ensuring full coverage of these rules?
Equivalence partitioning
Boundary value analysis
Decision table testing
Decision table testing explicitly maps combinations of multiple input conditions to specific outcomes. This ensures that every valid business rule defined in the specification is tested, providing a systematic approach to verifying complex logic and interactions between variables that simpler techniques would likely miss during design.
State transition testing
Which TWO of the following factors are critical when prioritizing test cases during the test design phase?
The number of test steps in the test procedure
The business risk of the associated requirements
Business risk is a primary driver for test prioritization. Functionality that carries significant financial or legal impact must be tested early and thoroughly. By focusing on requirements with high failure impact, the testing team ensures that critical organizational assets are protected against serious defects during the release cycle.
The estimated time taken to write the test case
The technical complexity of the feature
Technically complex features often harbor subtle defects that are difficult to identify. Prioritizing these areas early allows for more time to perform defect analysis and regression testing. Addressing these components early reduces the risk of discovering fundamental architectural flaws late in the project when remediation is costly.
The availability of the test automation tool
Refer to the exhibit. You are designing boundary value tests for an age validation field. What is the minimum set of test inputs that satisfy the 3-point boundary value analysis coverage criteria?
18, 65
17, 18, 19, 64, 65, 66
This set correctly implements 3-point boundary value analysis by selecting the boundary itself, the value just below, and the value just above for both defined limits. This ensures that the conditional operators (e.g., >= or <=) are verified against the adjacent values to confirm correct implementation.
0, 18, 65, 100
18, 19, 65, 66
Which activity is primary during the Test Analysis phase?
Creating test procedures
Identifying test conditions
Identifying test conditions is the core outcome of test analysis. By reviewing the test basis, testers create a list of items that require validation. This foundational step ensures that all requirements are accounted for and that the test coverage objectives are clearly defined before design starts.
Executing test scripts
Setting up the test environment
Want more Test Analysis and Design practice?
Practice this domainThe CTFL-v4 exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 6 domains: Fundamentals of Testing, Static Testing, Test Tools, Testing Throughout the SDLC, Managing the Test Activities, Test Analysis and Design. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISTQB CTFL-v4 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.