Courseiva
Fundamentals of Testing →hardMultiple Choice

CTFL-v4 Fundamentals of Testing Practice Question

Exhibit

POLICY_JSON: {"auth_mode": "SSO", "min_password_length": 12, "mfa_required": true, "session_timeout": 300}

Refer to the exhibit. A tester is validating this security policy. Which activity represents 'validation'?

⚠ Common exam trap

Candidates frequently confuse verification with validation, mistakenly picking code-checking tasks instead of activities that measure whether the system satisfies actual user needs and business goals.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Testing if the policy effectively prevents unauthorized access.

Validation confirms that the system meets user needs. By checking if the security policy actually protects the user's data and meets business security goals (e.g., does it actually prevent unauthorized access?), the tester is performing validation. This is distinct from verification, which would simply check if the code implements the JSON values as written without considering the broader business impact or the effectiveness of the security controls in a real environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Checking if the code correctly parses the JSON file.

    Why it's wrong here

    Checking if the JSON is parsed correctly is a verification activity. It ensures that the system handles the input format as specified by the technical design. It does not address whether the policy itself is appropriate for the business or if it effectively protects the application from real-world threats.

  • ✗

    Verifying that the password length is exactly 12 characters.

    Why it's wrong here

    Verifying that the implementation matches the requirement (12 characters) is a verification task. It checks internal consistency with the specification. It confirms the system was built 'right' according to the document but doesn't validate if a 12-character password is actually sufficient for the organization's security needs.

  • ✓

    Testing if the policy effectively prevents unauthorized access.

    Why this is correct

    Testing whether the policy effectively prevents unauthorized access is a validation activity. It evaluates whether the system fulfills the user's goal of security. If the policy is implemented correctly but fails to secure the system, it is a validation failure, even if the system is built correctly.

  • ✗

    Running a syntax check on the JSON configuration file.

    Why it's wrong here

    A syntax check ensures that the file format is valid JSON. This is a purely technical verification activity. It confirms the file is readable by the system but tells the tester nothing about whether the policy values inside the file are correct or if they meet the business's security requirements.

About these practice questions

Courseiva writes every CTFL-v4 question from scratch — 144 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISTQB exam blueprint

This CTFL-v4 practice question is part of Courseiva's free ISTQB certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CTFL-v4 exam.