Courseiva

CCNA Static Testing Questions

15 questions · Static Testing · All types, answers revealed

1
MCQmedium

What is the primary difference between a static analysis tool and dynamic testing in terms of their impact on the development process?

A.Static analysis is more accurate than dynamic testing for finding run-time logic errors.
B.Static analysis can be applied to code before it is fully executable.
C.Dynamic testing is cheaper to perform because it requires less setup.
D.Static analysis replaces the need for any form of functional testing.
AnswerB

Static analysis can be performed on individual components or partial codebases long before the entire system is integrated or ready for dynamic execution. This early feedback loop allows developers to fix structural or stylistic issues immediately, significantly reducing the cost and effort required for later integration testing.

Why this answer

Static analysis tools examine code without execution, identifying structural flaws, complexity issues, and coding standard violations early in the lifecycle. Dynamic testing requires a running system, detecting failures that occur during execution. By catching issues early, static analysis reduces the overall cost of rework, whereas dynamic testing validates the runtime behavior, making both essential components of a robust, comprehensive software quality assurance strategy.

Exam trap

Candidates often focus on the 'tools' aspect rather than the 'timing'. The most critical difference is that static analysis can occur before the code is even runnable.

2
MCQmedium

A software company is adopting static testing to reduce defect leakage. Which of the following scenarios best demonstrates the primary benefit of static testing over dynamic testing?

A.The testing team executes a test script to identify a logic error in the billing module.
B.Developers perform unit tests to verify that the API endpoints handle null inputs correctly.
C.A peer review of a technical specification document reveals an ambiguity that would lead to incorrect business logic.
D.A performance tool monitors system latency to ensure compliance with non-functional requirements.
AnswerC

This scenario highlights the core benefit of static testing: identifying defects early in the development lifecycle before code is written. By catching the ambiguity in the design phase, the team avoids the high cost of rework that would occur if the defect were discovered during dynamic testing.

Why this answer

Static testing finds defects early in the software development lifecycle, significantly reducing the cost of remediation compared to dynamic testing. By reviewing documentation, code, or requirements before execution, teams prevent defects from propagating into later phases. This approach improves overall software quality by addressing root causes in artifacts rather than just identifying symptoms in the running system, which is crucial for early risk mitigation.

Exam trap

Candidates often focus on the 'speed' of static testing rather than the 'cost-effectiveness' of catching defects before they are implemented into code.

3
MCQmedium

During a review process, a tester notices that the requirement document is ambiguous regarding how a specific error message should be displayed. What is the best course of action for the tester?

A.Assume the most logical implementation and document that in the test plan.
B.Report it as a defect in the requirement document during the review.
C.Ignore the ambiguity until the dynamic testing phase identifies it.
D.Ask the developer to decide how the error message should behave.
AnswerB

Documenting ambiguity as a defect is the correct procedure. Static testing aims to improve document quality; therefore, identifying gaps or vague language is a successful outcome. This forces the stakeholder or author to clarify the requirement, ensuring that development is based on accurate, unambiguous information from the start.

Why this answer

Clear communication is essential in static testing. Reporting the ambiguity as a defect is critical because ambiguous requirements lead to incorrect implementation. By documenting this as a defect, the tester ensures that the author must clarify the requirement before development begins.

This proactive approach prevents the developer from making incorrect assumptions, thereby saving time that would otherwise be spent on rework after the feature is implemented.

Exam trap

Candidates often assume testers should guess the developer's intent or wait until dynamic testing to uncover requirement ambiguities, missing the opportunity provided by static review.

4
MCQeasy

During a formal review process, which role is primarily responsible for documenting the defects found during the review meeting?

A.The Moderator
B.The Author
C.The Scribe
D.The Reviewer
AnswerC

The scribe is explicitly tasked with documenting all findings, defects, and suggestions identified during the meeting. This ensures a consistent record of the review outcomes, which is vital for the author to understand the necessary improvements required to meet the quality standards defined for the work product.

Why this answer

The scribe, or recorder, is responsible for documenting all issues, defects, and open points identified during the review meeting. This role ensures that all consensus items are captured accurately, allowing the author to address them during the rework phase. Having a dedicated scribe allows other participants, such as the moderator and reviewers, to remain focused on the technical discussion rather than administrative note-taking tasks.

Exam trap

Students often confuse the role of the moderator with the scribe, incorrectly assuming the meeting leader also documents all the identified defects during the review.

5
MCQmedium

When should static analysis be performed in the development lifecycle?

A.Only at the end of the project to ensure the final delivery is clean.
B.As early as possible, ideally during code development.
C.Only after the system has passed all functional testing phases.
D.Only when the code is deployed to the production environment.
AnswerB

Early integration allows for immediate detection and correction of code quality and security issues. This reduces the overall cost of defects, as they are easier to fix when the developer is still familiar with the code, leading to a more efficient development lifecycle.

Why this answer

Static analysis is most effective when performed as early and as often as possible. By integrating tools into the IDE or build pipeline, developers get immediate feedback, allowing them to fix issues before they even commit code. This continuous approach minimizes the effort required for remediation and ensures that the codebase maintains high quality, preventing technical debt from accumulating throughout the development process.

Exam trap

Candidates often select post-release or system testing phases, assuming static analysis is just another type of testing that requires code execution, completely missing the principle of early defect detection.

6
MCQmedium

Why is it important to include the author in the review meeting?

A.To allow the author to defend their design decisions against reviewer criticisms.
B.To provide explanations that help reviewers understand the logic and intent of the product.
C.To assign blame to the author for any defects discovered during the meeting.
D.To ensure the author can rewrite the code or document during the meeting.
AnswerB

The author can clarify complex areas, reducing the time reviewers spend guessing the intent of the documentation. This leads to more efficient defect detection and prevents reviewers from logging false positives based on a misunderstanding of the original design goals or business requirements.

Why this answer

The author is the primary source of truth regarding the intent and design of the work product. Their presence allows for immediate clarification of ambiguous points, which prevents misinterpretation by reviewers. While some argue for excluding authors to avoid defensiveness, the collaborative benefits of rapid clarification and shared understanding of the feedback typically outweigh those concerns in a professional and constructive review environment.

Exam trap

Candidates often prioritize the idea that the author's presence causes bias, overlooking the practical necessity of the author explaining intent to ensure reviewers don't misinterpret the documentation.

7
MCQmedium

Which of the following best describes the purpose of 'Entry Criteria' in a formal review process?

A.To determine which reviewers are qualified to participate in the session.
B.To provide a checklist that the author can use to fix defects found during the review.
C.To ensure that the work product is in a suitable state to be reviewed effectively.
D.To track the number of defects found by each individual reviewer during the meeting.
AnswerC

Entry criteria ensure that the document has reached a sufficient level of quality or completeness to warrant a formal review. This prevents reviewers from spending time on trivial issues or obvious errors, allowing them to focus on complex logic, requirements, or design issues during the meeting.

Why this answer

Entry criteria define the conditions that must be met before a review can commence, ensuring that the work product is ready for evaluation. This prevents wasting the time of reviewers on immature or incomplete documents, which would lead to unproductive sessions. By enforcing these criteria, the team maintains high standards and ensures that the review process is focused on identifying meaningful defects.

Exam trap

Candidates often think entry criteria are about the 'results' of the review, confusing them with exit criteria which define when the review process is considered successfully completed.

8
MCQhard

Refer to the exhibit. A static review of the JSON security policy reveals a critical configuration error. Which defect should the reviewer identify?

A.The 'max_attempts' value is set too high for a secure system.
B.The 'enforce_encryption' parameter is set to 'none'.
C.The 'timeout_seconds' value lacks a unit suffix.
D.The 'validate_user' flag should be set to 'false' for performance.
AnswerB

Disabling encryption in a policy configuration is a critical security risk. Static testing of configuration files is essential to catch these types of vulnerabilities before they reach an environment where they could be exploited, demonstrating the importance of reviewing infrastructure-as-code and configuration policies during the software development lifecycle.

Why this answer

The policy currently sets 'enforce_encryption' to 'none', which is a major security vulnerability for any production system. Static testing is uniquely capable of finding such configuration issues without executing the code. By reviewing the policy file during the design phase, the team can prevent potential data breaches that would arise if this configuration were deployed, illustrating the cost-effectiveness and preventive power of static testing methods.

Exam trap

Candidates may look for complex logic errors or syntax bugs, missing the obvious security misconfiguration. In a security policy, 'none' for encryption is a fatal, high-priority defect.

9
MCQmedium

Which of the following is a key success factor for any type of formal review?

A.The review must be conducted by external auditors to ensure objectivity.
B.The review must result in at least one defect per page of documentation.
C.The team must foster a supportive, constructive, and blame-free culture.
D.The author must be excluded from the meeting to prevent bias.
AnswerC

A culture that emphasizes learning and quality improvement encourages participants to be open about defects. In a blame-free environment, the author feels safe receiving feedback, and reviewers feel comfortable being critical, leading to a much more productive and effective review process.

Why this answer

A supportive and constructive culture is essential for successful reviews. When participants view the process as a collaborative effort to improve quality rather than a way to criticize or punish, they are more likely to participate openly. This trust allows for honest feedback and ensures that the primary goal—finding and fixing defects—is achieved effectively without causing interpersonal friction or defensive behavior.

Exam trap

Candidates often select 'finding the maximum number of defects' as the key success factor. While important, the culture is the prerequisite that allows those defects to be found openly.

10
MCQmedium

What is the primary difference between a 'Walkthrough' and an 'Inspection'?

A.A walkthrough is more formal than an inspection.
B.An inspection is primarily for defect finding, while a walkthrough is for learning.
C.A walkthrough requires a moderator and a scribe, but an inspection does not.
D.Inspections are never planned in advance, whereas walkthroughs are.
AnswerB

Inspections are designed to be rigorous, defect-finding activities with a documented process. Walkthroughs are generally intended for knowledge sharing, consensus building, and helping participants understand the work product, which makes them less effective for finding a large number of defects compared to an inspection.

Why this answer

An inspection is a formal, highly structured review process with specific roles and entry/exit criteria, aimed at identifying defects. A walkthrough is less formal, often led by the author to explain the logic to the team, focusing on shared learning and understanding rather than purely defect finding. This fundamental difference in purpose and process depth defines the choice of which review type to use in various situations.

Exam trap

Candidates often confuse the two because both are reviews. The key distinction is the primary objective: Inspections are formal for defect detection; Walkthroughs are informal for knowledge sharing.

11
MCQeasy

Which of the following is a primary objective of static analysis tools?

A.To execute the code with various test data inputs.
B.To identify potential security vulnerabilities and coding standard violations.
C.To measure the performance of the system under load.
D.To verify that the user interface meets design specifications.
AnswerB

Static analysis tools are designed to scan source code for patterns that indicate common security flaws, such as buffer overflows or injection risks, and to ensure code adheres to established standards. This automation ensures consistency and helps developers avoid common pitfalls before the code is ever compiled or run.

Why this answer

Static analysis tools analyze source code to find potential issues like security vulnerabilities, style violations, and structural complexity without executing the code. By automating this process, teams can enforce coding standards consistently across the entire codebase. This early detection mechanism is vital for maintaining high software quality and reducing the technical debt that would otherwise accumulate, ultimately leading to a more sustainable and manageable project over time.

Exam trap

Candidates often select objectives related to dynamic test execution, such as measuring response times or validating user interfaces, which static tools cannot perform without running the application.

12
MCQmedium

What is the primary goal of the 'Rework' phase in a formal review process?

A.To verify that the reviewers have understood the author's intent.
B.To correct identified defects and improve the work product.
C.To conduct a final assessment of the review's overall cost and time.
D.To finalize the project plan based on the findings.
AnswerB

Rework is the action taken by the author to rectify the defects flagged during the review. This is essential to ensure that the work product complies with the defined standards and requirements, ultimately improving the final quality of the output before it is used for subsequent phases.

Why this answer

The rework phase is dedicated to addressing the defects identified during the review. The author modifies the work product to correct the errors, incorporate suggestions, or clarify ambiguities based on the findings documented by the scribe. This ensures that the final artifact meets the quality requirements and is ready for the next stage of development, thereby preventing the defects from propagating further into the lifecycle.

Exam trap

Candidates often confuse 'Rework' with 'Follow-up'. Rework is the action taken by the author to fix the identified defects, whereas Follow-up is the verification that those fixes were actually implemented correctly.

13
MCQeasy

Which of the following is an example of an 'informal' review?

A.A structured inspection with a designated moderator and scribe.
B.A technical review conducted by a team with a predefined checklist.
C.A developer asking a colleague to look over their code for simple errors.
D.A formal walkthrough where the author explains the design to a group.
AnswerC

This is the classic example of an informal review. It is quick, involves no formal documentation, lacks defined roles like moderator or scribe, and is performed as an ad-hoc collaboration between peers, which is perfectly suited for small or low-risk development tasks.

Why this answer

Informal reviews are characterized by a lack of a formal process, documentation, or defined roles. They are often performed as simple peer-to-peer checks, such as two developers discussing a piece of code before a commit. This flexibility makes them very effective for quick feedback on small changes where the overhead of a formal process would be disproportionate to the risk or size of the task.

Exam trap

Examinees often look for formal documentation processes or entry/exit criteria, mistakenly ruling out casual peer reviews because they lack structured management oversight.

14
Multi-Selectmedium

Which TWO of the following statements accurately describe the role of the 'Moderator' in a formal inspection process?

Select 2 answers
A.The moderator acts as the lead author to explain complex sections.
B.The moderator ensures the inspection meeting is conducted efficiently.
C.The moderator is responsible for fixing all identified defects.
D.The moderator leads the review meeting and keeps the team focused.
E.The moderator must have the final sign-off authority for the project.
AnswersB, D

A key duty of the moderator is time management and process adherence. By keeping the meeting on track and ensuring participants focus on identifying issues rather than solving them, the moderator prevents wasted time and ensures the meeting remains productive and aligned with the established inspection objectives.

Why this answer

The moderator holds the primary responsibility for the success of the inspection. By managing the meeting and ensuring the process is followed, they shield the author from direct conflict and ensure participants focus on defect discovery rather than debating solutions. This separation of duties is vital for maintaining an objective, constructive, and efficient review environment, which is the cornerstone of successful formal static testing.

Exam trap

Candidates often confuse the moderator role with that of the author or scribe, mistakenly believing the moderator is responsible for fixing the discovered defects.

15
MCQmedium

Which TWO of the following statements accurately describe the characteristics of a formal review process?

A.Formal reviews must always include the participation of a test manager.
B.Formal reviews follow a documented process with defined roles and entry/exit criteria.
C.Formal reviews always require the use of automated static analysis tools.
D.Formal reviews result in a documented report of the findings and potential improvements.
E.Formal reviews are generally faster and cheaper than informal reviews.
AnswerB, D

A hallmark of formal reviews is the presence of a structured process, including specific roles like moderator and scribe. Entry and exit criteria ensure that the review is conducted efficiently and that the results meet the project's quality requirements before moving to the next stage.

Why this answer

Formal reviews are characterized by a structured process, documented results, and defined roles. They provide a disciplined approach to quality improvement by ensuring that participants follow specific procedures, such as preparation and a review meeting. These characteristics distinguish formal reviews from informal reviews, making them highly effective for ensuring compliance with standards and identifying critical defects in high-risk project artifacts throughout the development cycle.

Exam trap

Candidates frequently assume that formal reviews must be time-consuming or involve a large number of people, missing the key defining characteristics: documented processes, specific roles, and formal entry/exit criteria.

Ready to test yourself?

Try a timed practice session using only Static Testing questions.