ISTQB Certified Tester Foundation Level Free Sample Questions

20 free sample questions262 in the full practice test

Try simulator

CTFL Sample Questions

  1. Question 1

    During a project retrospective for a new mobile banking application developed using Scrum, the test lead notes that a significant number of defects related to transaction processing were found late in the sprint, during system testing. To improve early defect detection in future sprints, which testing practice should be more heavily emphasized?

    Answer and explanation

    Correct answer: B

    The principle of 'shift left' encourages moving testing activities earlier in the lifecycle. By performing more thorough component and component integration testing as soon as code is available, defects can be found and fixed closer to when they were introduced. This is more efficient and prevents them from escalating into more complex issues found during system testing. UAT is too late, maintenance testing is post-release, and static analysis alone might miss runtime integration issues.

  2. Question 2

    Multiple answers

    A software development team is building an Internet of Things (IoT) solution for smart home automation. The system involves hardware sensors, a central hub, a cloud-based data processing service, and a mobile application. Which TWO of the following test types are MOST critical for ensuring the end-to-end quality of this system? (Select TWO).

    Answer and explanation

    Correct answers: B, D

    Interoperability testing is crucial for an IoT system to ensure that the diverse components (sensors, hub, cloud, mobile app), which may be from different vendors or use different protocols, can communicate and work together correctly.

    Security testing is paramount for IoT devices as they are often targets for cyber-attacks. Ensuring data privacy, secure communication between devices and the cloud, and protection against unauthorized access is a critical non-functional requirement.

  3. Question 3

    During a project to develop a safety-critical avionics system, the requirements specification is scheduled for a formal inspection. Which of the following is a key characteristic that distinguishes an inspection from other review types like a walkthrough or an informal review?

    Answer and explanation

    Correct answer: C

    Inspections are the most formal type of review. They are characterized by a rigorously defined process, specified entry and exit criteria, formal roles (like Moderator, Scribe, Reviewer), and the collection of metrics to improve both the product and the review process itself. The author does not lead the meeting, and the primary goal is defect detection, not brainstorming.

  4. Question 4

    A project manager is concerned about the high cost of test environment setup and maintenance. Adopting a new test automation framework is being considered. Which of the following represents the MOST significant potential risk of introducing test automation that the manager must consider?

    Answer and explanation

    Correct answer: B

    A major risk in test automation is setting unrealistic expectations. Stakeholders may believe automation is a 'silver bullet' that replaces manual testing entirely and finds all bugs. In reality, automation is best for repetitive tasks like regression testing, but it requires significant investment in creation and maintenance, and it is not a substitute for the critical thinking and exploratory abilities of a manual tester.

  5. Question 5

    A system for controlling a medical infusion pump has passed 100% of its requirement-based tests. However, a safety audit reveals that a specific, complex combination of user inputs, not specified in the requirements, can lead to a dangerous overdose. This scenario best illustrates which testing principle?

    Answer and explanation

    Correct answer: C

    The absence-of-errors fallacy states that finding and fixing a large number of defects does not guarantee the success of a system if the system itself does not meet user needs or is unusable. In this case, even though all specified requirements were tested and passed (absence of errors), the system was still unsafe because the requirements missed a critical real-world scenario. Verification (testing against requirements) was done, but validation (ensuring it's fit for purpose) failed.

  6. Question 6

    A project is behind schedule, and management is pressuring the test team to sign off on a release. The test manager's dashboard shows that while 95% of planned test cases have been executed, the test coverage on the highest-risk modules is only at 60%. Several high-severity defects remain open. Which of the following is the MOST appropriate action for the test manager to take?

    Answer and explanation

    Correct answer: C

    The role of the test manager is not to unilaterally approve or block a release but to provide clear, data-driven information to stakeholders so they can make an informed business decision. The most professional and appropriate action is to communicate the exact testing status, including coverage of high-risk areas and the specific residual risks (open defects, untested areas). This allows stakeholders to formally accept the risk before proceeding.

  7. Question 7

    Multiple answers

    A test analyst is writing a defect report for a crash that occurs when uploading a file. To ensure the developers can reproduce and fix the issue efficiently, which THREE of the following items are MOST essential to include in the defect report? (Select THREE).

    Answer and explanation

    Correct answers: B, D, E

    A good title (e.g., 'Crash on file upload with >10MB PNG file') immediately informs the developer of the problem's nature and context.

    This is the most critical part of a defect report. Without clear, repeatable steps, the developer may be unable to find, diagnose, or fix the bug.

    Clearly stating what happened (actual result: 'Application crashes') versus what should have happened (expected result: 'File uploads successfully and a confirmation message appears') defines the failure and removes ambiguity.

  8. Question 8

    A developer runs a static analysis tool (linter) on their source code before committing it to the repository. The tool reports a potential null pointer exception on a rarely used code path. This activity is an example of:

    Answer and explanation

    Correct answer: C

    Static testing involves examining work products (like source code) without executing them. Static analysis tools automate this process by checking the code against predefined rules and patterns to find potential defects, such as the null pointer exception mentioned. It is not dynamic testing because the code was not run.

  9. Question 9

    True or False: The primary purpose of confirmation testing (re-testing) is to ensure that a bug fix has not introduced new defects in other areas of the application.

    Answer and explanation

    Correct answer: B

    This statement describes regression testing. The primary purpose of confirmation testing is to verify that the original reported defect has been successfully fixed. Regression testing is the separate activity performed to check for unintended side effects (new defects) in unchanged parts of the software.

  10. Question 10

    A project is developing a customer relationship management (CRM) system. The lead tester is creating the master test plan. Which of the following is an example of a PRODUCT risk, as opposed to a project risk?

    Answer and explanation

    Correct answer: C

    Product risks are related to the quality and characteristics of the software itself (what it does). A failure to secure data is a quality issue inherent to the product. Project risks are related to the management and execution of the project (how it's built), such as staff leaving, budget cuts, or schedule delays.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 262 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon