Skip to content

CTFL Practice Questions

Prepare for CTFL with more than an answer.

262 questions in the full set20 sample questionsUpdated Jan 11, 2026
Exam fee
$229 USD
Level
Foundation
Valid for
lifetime
Domains covered on the exam 6
  1. Fundamentals of Testing20%
  2. Testing Throughout the Software Development Lifecycle15%
  3. Static Testing10%
  4. Test Analysis and Design27.5%
  5. Managing the Test Activities22.5%
  6. Test Tools5%
  1. 1

    A test team is about to start the system testing phase for a new enterprise resource planning (ERP) system. The test manager states that testing cannot begin until the test environment is fully configured, the test data has been loaded, and all features planned for the release have been successfully unit tested. This statement is an example of defining:

    Show answer details

    Correct answer: D

    Entry criteria are the set of conditions that must be met before a test phase or activity can begin. The examples given (stable environment, available test data, readiness of the test object) are all preconditions for starting the system testing phase.

  2. 2

    Which of the following describes the difference between system testing and system integration testing?

    Show answer details

    Correct answer: D

    System testing evaluates the behavior of the entire, integrated system against its specified requirements. System integration testing specifically focuses on the interactions and interfaces between the system under test and other external systems, such as third-party APIs, databases, or microservices.

  3. 3

    During a planning poker session for an Agile project, a user story is estimated by three developers with scores of 3, 5, and 13. What is the MOST appropriate next step for the team to take?

    Show answer details

    Correct answer: D

    Planning poker is an expert-based estimation technique (related to Wideband Delphi) designed to reach consensus. A wide divergence in estimates (like 3 vs. 13) indicates that team members have different understandings or assumptions about the work involved. The core of the process is the discussion that follows the vote, where the high and low estimators explain their rationale. This conversation is crucial for clarifying requirements and risks before re-voting.

  4. 4

    A test manager is reviewing the test progress report and notices that the number of new defects being found per week is steadily decreasing, while the number of fixed defects is increasing. What does this trend likely indicate about the software's quality?

    Show answer details

    Correct answer: B

    This trend is a common indicator of improving software quality. As testing progresses, the most obvious defects are found and fixed. The rate of finding new defects naturally slows down as the product becomes more stable. When the rate of fixing defects surpasses the rate of finding new ones, it often suggests that the software is converging towards the quality goals defined in the exit criteria.

  5. 5

    Case Study: Cloud Migration

    A financial services company is migrating its on-premises customer data application to a cloud-native microservices architecture. The migration will happen in phases over six months. The new architecture consists of a user interface service, an authentication service, a customer data service, and a reporting service. Each service is developed and deployed independently.

    The test team needs to ensure that after each phase of migration, the independently deployed services can still communicate correctly with each other and with any remaining on-premises components. For example, they must verify that the new cloud-based authentication service can correctly provide tokens that the new customer data service will accept.

    What is the MOST critical type of testing required to validate the interaction between these services throughout the migration project?

    graph TD subgraph On-Premises LegacyDB[(Legacy DB)] end subgraph Cloud Environment Auth[Authentication Service] Customer[Customer Data Service] UI[UI Service] end UI --> Auth UI --> Customer Customer --> Auth Customer --> LegacyDB

    Show answer details

    Correct answer: B

    The scenario describes testing the interfaces and interactions between independently deployed services (microservices) and other system parts. This is the definition of component integration testing (or simply integration testing in this context). While component testing verifies each service in isolation, integration testing is essential to ensure they work together correctly, especially in a complex, phased migration.

  6. 6

    During a project retrospective for a new mobile banking application developed using Scrum, the test lead notes that a significant number of defects related to transaction processing were found late in the sprint, during system testing. To improve early defect detection in future sprints, which testing practice should be more heavily emphasized?

    Show answer details

    Correct answer: C

    The principle of 'shift left' encourages moving testing activities earlier in the lifecycle. By performing more thorough component and component integration testing as soon as code is available, defects can be found and fixed closer to when they were introduced. This is more efficient and prevents them from escalating into more complex issues found during system testing. UAT is too late, maintenance testing is post-release, and static analysis alone might miss runtime integration issues.

  7. 7

    A software development team is building an Internet of Things (IoT) solution for smart home automation. The system involves hardware sensors, a central hub, a cloud-based data processing service, and a mobile application. Which TWO of the following test types are MOST critical for ensuring the end-to-end quality of this system? (Select TWO).

    Show answer details

    Correct answer: D, E

    Security testing is paramount for IoT devices as they are often targets for cyber-attacks. Ensuring data privacy, secure communication between devices and the cloud, and protection against unauthorized access is a critical non-functional requirement.

    Interoperability testing is crucial for an IoT system to ensure that the diverse components (sensors, hub, cloud, mobile app), which may be from different vendors or use different protocols, can communicate and work together correctly.

  8. 8

    During a project to develop a safety-critical avionics system, the requirements specification is scheduled for a formal inspection. Which of the following is a key characteristic that distinguishes an inspection from other review types like a walkthrough or an informal review?

    Show answer details

    Correct answer: A

    Inspections are the most formal type of review. They are characterized by a rigorously defined process, specified entry and exit criteria, formal roles (like Moderator, Scribe, Reviewer), and the collection of metrics to improve both the product and the review process itself. The author does not lead the meeting, and the primary goal is defect detection, not brainstorming.

  9. 9

    A project manager is concerned about the high cost of test environment setup and maintenance. Adopting a new test automation framework is being considered. Which of the following represents the MOST significant potential risk of introducing test automation that the manager must consider?

    Show answer details

    Correct answer: C

    A major risk in test automation is setting unrealistic expectations. Stakeholders may believe automation is a 'silver bullet' that replaces manual testing entirely and finds all bugs. In reality, automation is best for repetitive tasks like regression testing, but it requires significant investment in creation and maintenance, and it is not a substitute for the critical thinking and exploratory abilities of a manual tester.

  10. 10

    A system for controlling a medical infusion pump has passed 100% of its requirement-based tests. However, a safety audit reveals that a specific, complex combination of user inputs, not specified in the requirements, can lead to a dangerous overdose. This scenario best illustrates which testing principle?

    Show answer details

    Correct answer: C

    The absence-of-errors fallacy states that finding and fixing a large number of defects does not guarantee the success of a system if the system itself does not meet user needs or is unusable. In this case, even though all specified requirements were tested and passed (absence of errors), the system was still unsafe because the requirements missed a critical real-world scenario. Verification (testing against requirements) was done, but validation (ensuring it's fit for purpose) failed.

Create an account to continue.