Courseiva

CCNA Testing Throughout the SDLC Questions

20 questions · Testing Throughout the SDLC · All types, answers revealed

1
MCQhard

Refer to the exhibit. During static testing, a tester identifies that the 'lockout_duration_mins' is set to 15. What is the most likely risk identified by the tester?

A.The password length requirement is too short and will cause an execution error.
B.The lockout duration is a configuration parameter that doesn't impact security.
C.The policy needs to be reviewed against security requirements to determine if it is appropriate.
D.The system will fail to compile because the policy is written in JSON format.
AnswerC

Static analysis of the policy involves comparing it to the project's security requirements. Whether 15 minutes is appropriate depends on the application's risk profile. The tester's role is to ensure the team validates this configuration against business and security goals before it is implemented in the actual code.

Why this answer

A static review of security policies identifies vulnerabilities before they are deployed. A 15-minute lockout might be too short for effective brute-force protection or too long for legitimate user usability, depending on the risk model. Identifying these policy gaps during the design phase allows the team to adjust security settings to balance security and usability without requiring costly code changes post-deployment.

Exam trap

Candidates often assume a specific configuration value like 15 minutes is inherently correct or incorrect without realizing that static testing requires reviewing it against business and security requirements.

2
MCQmedium

Which of the following scenarios best demonstrates the concept of 'Shift-Left' testing?

A.The test team performs extra rounds of testing at the end.
B.Testers participate in user story refinement sessions.
C.Developers ignore testing until the code is fully deployed.
D.The test team uses the same test cases throughout the lifecycle.
AnswerB

Participating in refinement sessions is a key shift-left activity. It allows testers to clarify requirements, anticipate potential edge cases, and define acceptance criteria before development starts. This early involvement ensures that the team has a shared understanding of what 'done' looks like and helps prevent defects from occurring.

Why this answer

Shift-left testing refers to moving testing activities earlier in the SDLC. By involving testers in requirements gathering and design reviews, teams can catch structural and logical defects before code is written. This approach reduces the cost of development and ensures that quality is embedded into the product from the start, rather than being an afterthought that is only addressed in the final stages of the project.

Exam trap

Test-takers often select early automated test execution, missing that shift-left specifically emphasizes moving testing activities into requirements analysis and user story refinement.

3
MCQeasy

What is the primary difference between confirmation testing and regression testing?

A.Regression testing is only for automated scripts.
B.Confirmation testing focuses on the fix; regression on the system.
C.Regression testing is performed before the bug is fixed.
D.Confirmation testing is a form of negative testing.
AnswerB

Confirmation testing aims to prove that the specific defect reported is no longer present. Regression testing, however, is broader; it checks the entire system to ensure that the code changes did not cause unintended side effects or break features that were previously working as expected.

Why this answer

Confirmation testing (re-testing) confirms that a specific defect has been fixed. Regression testing ensures that the fix—or any other change—has not broken previously working functionality. Understanding this distinction is vital for testers to properly manage their test suites and ensure that they are verifying both the resolution of reported bugs and the overall stability of the existing system after changes.

Exam trap

Candidates frequently use confirmation testing and regression testing interchangeably, failing to distinguish between verifying a specific fix and checking overall system stability.

4
MCQmedium

A system is being developed using an incremental model. During which testing stage should the team verify that the new increment correctly integrates with the existing system functionality?

A.Acceptance testing of the new increment only.
B.System integration testing.
C.Unit testing of the new increment.
D.Static testing of the design documents.
AnswerB

System integration testing is the most appropriate stage to verify that the new increment, when combined with the existing codebase, maintains overall system integrity. It ensures that the interfaces are correctly connected and that the system as a whole functions as expected after the addition.

Why this answer

In an incremental model, each new increment must be integrated into the existing stable codebase. Integration testing is the specific activity that validates the interfaces and communication between the new parts and the old ones. This ensures that the system as a whole remains functional, preventing regressions and ensuring that the newly added features are correctly supported by the existing architecture.

Exam trap

Test-takers often confuse component integration testing with system integration testing, failing to recognize that combining an entire new increment with an existing system requires system integration testing.

5
MCQmedium

In an Agile project, a developer completes a feature and commits the code. Which testing activity should occur immediately to ensure the new code does not break existing functionality while maintaining project velocity?

A.Acceptance testing by the product owner.
B.System integration testing against all legacy systems.
C.Automated regression testing.
D.Manual exploratory testing of the entire application.
AnswerC

Automated regression testing is the most efficient way to verify that new code additions have not introduced defects into existing, previously verified features. It provides immediate feedback to developers, which is crucial for maintaining the fast-paced delivery cycles inherent in Agile software development processes.

Why this answer

Regression testing is critical in Agile because frequent code changes can inadvertently impact stable features. Automating these tests allows for rapid feedback and ensures that the build remains stable throughout the continuous integration cycle. By integrating these tests into the CI/CD pipeline, the team maintains high velocity without sacrificing the quality of the existing codebase, which is essential for iterative development environments.

Exam trap

Candidates often select manual exploratory testing or system acceptance, forgetting that Agile continuous integration relies heavily on automated regression testing for speed and stability.

6
Multi-Selectmedium

Which THREE of the following are benefits of static testing early in the SDLC?

Select 3 answers
A.Reduced cost of quality by finding defects before they are implemented in code.
B.Elimination of the need for any dynamic testing in the later stages.
C.Early identification of missing or ambiguous requirements.
D.Increased understanding of the system by testers, leading to better test design.
E.Automated code coverage analysis of the requirement document.
AnswersA, C, D

Identifying defects in requirements or design is significantly cheaper than fixing them once they have been implemented. By catching errors during static testing, the team avoids the downstream costs associated with debugging, code rework, re-testing, and potential project delays, leading to a much more cost-effective development process.

Why this answer

Static testing is the most powerful tool for defect prevention. By analyzing documentation before implementation, teams can identify errors that are cheap to fix. It also clarifies requirements, improves communication, and provides a head start on test planning.

These benefits compound throughout the SDLC, reducing rework and ensuring the final product matches the intended design and user requirements.

Exam trap

Candidates often assume static testing is only about finding bugs in code, ignoring that it also covers documentation, requirements, and design to prevent defects before any code is actually written.

7
MCQmedium

How does early test planning benefit the development process?

A.It ensures that the developers have less work to do because testers find all the bugs.
B.It facilitates the identification of test requirements and potential environment constraints early.
C.It removes the need for communication between the development and testing teams.
D.It makes it impossible to change requirements once the project has started.
AnswerB

Early planning allows the team to identify exactly what needs to be tested and what resources, such as hardware or tools, are required. Catching environment constraints early prevents delays that often occur when testers realize they lack the necessary test infrastructure right before the testing phase begins, ensuring a smoother development process.

Why this answer

Early test planning helps define the scope, resources, and schedule for testing. By identifying these needs early, the team can ensure that the environment is ready and that testing is fully integrated into the development cycle. It also clarifies the 'definition of done,' ensuring that everyone is working toward the same quality objectives, which reduces friction during the final stages of the release cycle.

Exam trap

Students often pick options related to writing final test scripts or executing test cases, overlooking the fact that early planning focuses on requirements and environment constraints.

8
MCQeasy

What is the primary objective of static testing in the software development lifecycle?

A.To identify performance issues that might impact system scalability.
B.To find defects in the software before it is executed.
C.To verify that the software meets all functional requirements through execution.
D.To generate test data for future automated testing sessions.
AnswerB

Static testing aims to find defects in work products other than the executable code, such as requirements documents, design specifications, or test plans. Finding these defects early prevents them from propagating into the implementation phase, which is a fundamental and proactive aspect of the testing process.

Why this answer

The main goal of static testing is defect prevention. By identifying issues in documentation, requirements, and design early, it prevents these errors from being translated into software defects. This is highly efficient, as it is much cheaper to fix a requirement error on paper than a bug in the code, contributing significantly to overall project quality and cost-effectiveness.

Exam trap

Candidates often confuse static testing with 'manual testing'. They assume static testing is just manual execution, ignoring the crucial aspect that code is not executed at all.

9
MCQhard

Refer to the exhibit. The log shows a recurring sequence in a test environment. What does this suggest about the 'Testing throughout the SDLC' approach applied here?

A.The test team successfully implemented automated recovery procedures.
B.The memory leak was identified and resolved during the early development phase.
C.Testing failed to catch a performance/resource defect, leading to a symptomatic workaround.
D.The log level configuration is too strict, causing unnecessary restarts.
AnswerC

The sequence of events shows a performance bottleneck causing a failure. The restart is a symptomatic workaround, not a solution. The failure to catch this earlier in the SDLC demonstrates that the testing process was not rigorous enough regarding non-functional performance requirements or resource management during integration and testing cycles.

Why this answer

The logs indicate that system stability issues are being treated with a 'restart' mechanism, masking the root cause (a memory leak or resource exhaustion). A proper testing approach should have identified this memory trend during component or integration testing. Relying on service restarts in production is a failure of testing to identify and advocate for fixing underlying architectural defects early in the life cycle.

Exam trap

Candidates often believe that using automated restarts in production is a valid testing outcome, missing that it acts as a symptomatic workaround masking an underlying defect.

10
MCQhard

Refer to the exhibit. A tester sees this error during load testing. Based on the principle of 'Testing throughout the SDLC', what should be the immediate recommendation?

A.Ignore the error as it only occurs under high load, which is not the primary focus.
B.Increase the number of threads in the API gateway to mask the timeout.
C.Conduct a root cause analysis on the connection pool configuration and design.
D.Immediately roll back the last code deployment to the production environment.
AnswerC

Root cause analysis addresses the source of the timeout. By examining the connection pool, the team can determine if it is a configuration issue or a design flaw, such as failing to close connections properly. This systematic approach ensures long-term stability and aligns with the professional testing responsibility.

Why this answer

Load testing identifies performance bottlenecks that won't appear in unit tests. A connection pool exhaustion indicates architectural or configuration issues that must be addressed at the infrastructure or design level. Recommending a review of the design or configuration ensures the fix is structural, rather than a superficial band-aid, adhering to the shift-left focus on addressing root causes early in the life cycle.

Exam trap

Candidates often suggest a quick fix like 'restarting the server' instead of 'root cause analysis', failing to apply the principle of shift-left testing for long-term quality.

11
MCQmedium

Which of the following activities is a characteristic of 'Static Testing' within the Software Development Life Cycle?

A.Executing test cases against a running application.
B.Performing a technical review of the design specification.
C.Measuring the code coverage during unit testing.
D.Running automated integration tests in the CI/CD pipeline.
AnswerB

A technical review of design specifications is a form of static testing. It allows stakeholders and developers to identify logic errors, ambiguities, or missing requirements before a single line of code is written, ensuring that the development team works from a complete and accurate set of documentation.

Why this answer

Static testing involves examining work products without executing code. It is an essential part of the SDLC because it allows for early defect detection in documents like requirements, design, or user stories. By finding issues in the planning phase, the cost of fixing those defects is significantly lower compared to finding them after the code is deployed to a dynamic environment.

Exam trap

Candidates frequently select dynamic execution activities like running unit tests or executing scripts, confusing static testing with component testing.

12
Multi-Selecthard

Which TWO of the following statements accurately describe the role of testers in a modern SDLC?

Select 2 answers
A.Testers are solely responsible for all quality activities within the project.
B.Testers contribute by helping to define the acceptance criteria for user stories.
C.Testers should focus exclusively on dynamic testing to prove the system works.
D.Testers facilitate the communication between technical and business stakeholders.
E.Testers should avoid participating in code reviews to remain unbiased.
AnswersB, D

Testers help refine requirements by ensuring acceptance criteria are clear, measurable, and testable. By participating early, they identify edge cases and potential ambiguities, ensuring that the team understands exactly what needs to be built and verified, which significantly reduces the risk of misunderstood requirements and downstream defects.

Why this answer

Modern testing emphasizes collaboration and early involvement. Testers serve as quality advocates who help define 'done' and verify that requirements are testable. By participating in reviews and planning, they facilitate a shared understanding of quality across the entire team, which is essential for successfully delivering software in iterative and incremental development environments.

Exam trap

Candidates often cling to the outdated view that testers only 'find bugs' after development, ignoring the modern shift towards collaboration, requirements definition, and stakeholder communication.

13
MCQhard

Refer to the exhibit. An automated test suite produces these logs. Which testing phase is most likely to catch this type of defect, and why?

A.Component testing, because it verifies the code logic.
B.Integration testing, because it validates module communication.
C.Acceptance testing, because it tests business requirements.
D.Static testing, because it reviews the source code.
AnswerB

Integration testing is specifically designed to test the interfaces and connections between components. This log shows a failure in the communication layer between the application and the AuthServer, which is a textbook example of an issue that should be caught when verifying the system's integration points.

Why this answer

This log indicates a recurring connection timeout, which is a classic symptom of poor integration between the application and an external service. While unit tests might pass if they use mocks, integration testing is designed to verify the actual communication path. Catching this during integration testing ensures that environmental dependencies and real network configurations are validated before the system moves into the more complex system testing phase.

Exam trap

Candidates frequently select unit testing because timeouts involve specific code functions, ignoring that connection timeouts stem from communication between modules or external services.

14
Multi-Selectmedium

Which TWO of the following are valid reasons for performing maintenance testing?

Select 2 answers
A.To verify that a bug fix has been successfully implemented.
B.To replace all existing test cases with new ones.
C.To test the system after a migration to a new platform.
D.To prevent the need for any future updates.
E.To eliminate the need for documentation updates.
AnswersA, C

When a bug is fixed, confirmation testing is performed to verify the fix, followed by regression testing to ensure the change did not introduce new issues. This is a core part of maintenance testing, ensuring the integrity of the existing system after a patch or update is applied.

Why this answer

Maintenance testing is performed when an existing system is modified, migrated, or retired. Even minor changes, like a configuration update or a library patch, can introduce unintended regressions. By performing maintenance testing, organizations ensure that the new changes don't break existing features and that the system continues to perform reliably in its production environment after modifications have been applied.

Exam trap

Candidates often mistakenly believe maintenance testing only applies to major upgrades, ignoring that bug fixes and environment migrations also require formal maintenance testing cycles.

15
MCQmedium

In the context of the 'Test-First' approach, how does the developer's role change regarding testing?

A.The developer no longer needs to perform debugging.
B.The developer writes tests to define functionality before writing the code.
C.The developer delegates all testing responsibilities to the QA team.
D.The developer waits for a test plan to be approved by the test manager.
AnswerB

Writing tests before the code is the core mechanic of Test-Driven Development. This approach defines the expected outcome of the code, helps clarify the requirements, and establishes a clear success criterion for the implementation, resulting in higher quality code that is easier to maintain and refactor.

Why this answer

In a Test-First approach (like TDD), the developer writes the test case before writing the corresponding application code. This forces the developer to understand the requirements and the expected behavior of the code before implementation begins. This practice leads to cleaner, more modular code design and ensures that every piece of functionality has a verified, automated test case from the very beginning of the development cycle.

Exam trap

Candidates often mistake test-first for 'writing tests after the code is finished', missing the core concept that tests act as the specification for the code to be written.

16
MCQmedium

Which testing role is primarily responsible for ensuring that the testing strategy aligns with the SDLC chosen for the project?

A.The Software Developer.
B.The Test Manager.
C.The Business Analyst.
D.The Product Owner.
AnswerB

The Test Manager is responsible for the overall testing strategy. This includes choosing the right testing levels, methods, and tools to match the chosen SDLC. They ensure that testing is both effective and efficient, adjusting their management approach to suit the specific needs of the development project.

Why this answer

The Test Manager is responsible for defining the testing strategy and ensuring it integrates correctly with the project's chosen SDLC. They must adapt the testing approach to fit the development life cycle—such as selecting automated CI/CD tools for Agile projects or formal documentation reviews for V-model projects—to ensure that testing supports the team's goals and provides relevant feedback at the right time.

Exam trap

Candidates often choose the 'Test Analyst' or 'Test Lead', assuming the role is purely technical. They fail to recognize that strategy alignment is a management-level responsibility.

17
MCQmedium

Which of the following describes the 'Testing' activity in the context of the V-model?

A.Testing is a distinct phase that occurs only after the final system integration.
B.Testing activities correspond to specific development phases, starting at the requirements level.
C.Testing is used solely for defect detection at the very end of the development process.
D.Testing consists only of the execution of automated scripts against the finished code.
AnswerB

The V-model explicitly maps each development phase to a testing level. Requirements analysis is verified by acceptance testing, design by system testing, and so on. This alignment ensures that testing starts early, is traceable to requirements, and provides a clear mechanism for verifying the system at every level.

Why this answer

The V-model emphasizes the relationship between each development phase and a corresponding testing phase. In this model, testing is not just a final stage; it is a parallel activity that starts with planning and design. This ensures that every development requirement has a corresponding verification method, providing a structured approach to quality assurance throughout the entire SDLC.

Exam trap

Candidates often think V-model testing happens only after coding is complete, ignoring the fact that the V-model maps testing activities to every development phase, including requirements.

18
MCQmedium

Which of the following activities best demonstrates the ISTQB principle of 'Testing provides early feedback'?

A.Executing automated regression tests at the end of each daily build.
B.Reviewing user stories and acceptance criteria during the sprint planning session.
C.Conducting a performance test on the integrated system before the final release.
D.Reporting defects found during the User Acceptance Testing (UAT) phase.
AnswerB

Reviewing requirements during planning is a classic example of static testing. It provides immediate feedback to the product team, allowing them to clarify requirements, identify missing test conditions, and ensure the criteria are measurable. This activity prevents defects from being injected into the development process later on.

Why this answer

Early feedback is the core of shift-left testing. By performing static testing on documents like requirements or design specifications, testers identify defects before a single line of code is written. This is more efficient and cost-effective than finding defects during dynamic testing, as it prevents the cost of rework and ensures that quality is built into the product from the very start of development.

Exam trap

Candidates often confuse 'early feedback' with 'early execution' of automated tests, failing to realize that static testing (reviews) is the most effective way to provide feedback before any code exists.

19
MCQmedium

Which approach is most appropriate for maintaining quality when a project uses a DevOps culture with continuous deployment?

A.Manual exploratory testing of every build before it is moved to production.
B.Automated regression tests integrated into the pipeline combined with production monitoring.
C.Performing formal, document-heavy system testing cycles after every code merge.
D.Requiring a separate QA phase where developers are not involved in testing.
AnswerB

Automated pipelines provide rapid verification of code changes, while production monitoring acts as a safety net. This dual approach ensures that defects are caught early in the development cycle and that any issues escaping to production are identified and addressed immediately, supporting a stable, high-speed release process.

Why this answer

In continuous deployment, testing must be highly automated and integrated into the CI/CD pipeline. Shifting testing to the left ensures that code quality is verified at every commit, while monitoring provides the final feedback loop. This combination allows for rapid releases without sacrificing quality, which is the primary objective of DevOps and modern continuous testing practices.

Exam trap

Candidates often select 'manual exploratory testing' as the primary approach, which is too slow and inconsistent for a continuous deployment pipeline requiring rapid, repeatable feedback.

20
MCQhard

Refer to the exhibit. A tester reviews this configuration file during the static testing of a test environment setup. What is the primary risk of this configuration in a formal testing phase?

A.The log level set to debug will cause an overflow error in the production database.
B.The exponential retry policy will increase the latency of the system during stress testing.
C.The disabled strict mode may allow invalid data to be processed, masking bugs.
D.The environment tag set to 'dev' indicates that the deployment is insecure by design.
AnswerC

Disabling strict mode allows the system to ignore data validation errors or schema violations. This masks defects that would trigger critical errors in a production environment where strict mode is enabled. Static testing of configuration files is essential to ensure the environment supports valid test execution and defect detection.

Why this answer

Testing requires stable and representative environments. The 'strict_mode: false' setting allows suboptimal code paths or weak error handling to pass, which should fail in production. Finding this via static testing prevents 'false negatives' where the system appears stable in testing due to permissive settings.

Ensuring the test environment configuration mirrors production requirements is a critical aspect of early SDLC validation and risk management.

Exam trap

Candidates often focus on the technical error itself rather than the risk that the environment is not representative of production, which invalidates the testing results.

Ready to test yourself?

Try a timed practice session using only Testing Throughout the SDLC questions.