Testing & Quality Disciplines
The vocabulary and practice of software quality: test levels and the pyramid, test doubles, test structure and independence, case-design techniques, coverage and its limits, TDD and BDD, and static analysis. Interviewers cover this because every role writes tests, and how you talk about them reveals how you work.
on this pageshowhide
explore
- Testing85 questions
- Levels of Testing24 questions
- Test Doubles14 questions
- Test Structure13 questions
- Test Design Techniques20 questions
- Coverage & Test Quality14 questions
- Test-Driven Development25 questions
- Red-Green-Refactor Cycle4 questions
- Test-First Design4 questions
- Small Steps and Triangulation3 questions
- Emergent Design4 questions
- Refactoring Under Tests4 questions
- Common Pitfalls3 questions
- Outside-In vs Inside-Out3 questions
- Behavior-Driven Development29 questions
- Given-When-Then Structure5 questions
- Gherkin Syntax4 questions
- Three Amigos Collaboration4 questions
- Executable Specifications4 questions
- Living Documentation4 questions
- Scenario Suite Maintenance4 questions
- Double-Loop Acceptance Cycle4 questions
- Static Analysis & Linting19 questions
- Lint Rules & Philosophy3 questions
- Static Type Checking4 questions
- SAST & Taint Tracking4 questions
- Baselines & Suppression3 questions
- CI & IDE Integration5 questions
- Test Planning & Governance55 questions
- Risk-Based Selection4 questions
- Strategy & Plan Documents4 questions
- Entry & Exit Criteria4 questions
- Lifecycle Models4 questions
- Shift-Left Practices4 questions
- Regression & Smoke Suites4 questions
- Test Effort Estimation4 questions
- Progress Tracking4 questions
- Requirements Traceability23 questions
- Defect Management31 questions
- Bug Report Anatomy3 questions
- Severity vs Priority3 questions
- Triage & Lifecycle4 questions
- Origin & Escape Phase5 questions
- Density & Removal Rates4 questions
- Root Cause Analysis12 questions
- Non-Functional Testing60 questions
- Performance Workloads40 questions
- Resilience & Recovery3 questions
- Platform Compatibility5 questions
- Locale Readiness4 questions
- Abuse & Negative Cases4 questions
- Data Volume Growth4 questions
- Exploratory & Manual Testing25 questions
- Unscripted Discovery4 questions
- Timeboxed Sessions5 questions
- Mission Charters3 questions
- Oracles & Heuristics4 questions
- Bug Advocacy5 questions
- Bug Bashes & Crowd Testing4 questions
- Automation Strategy195 questions
- Choosing What to Automate4 questions
- API-Level Case Design4 questions
- Data & Keyword Frameworks3 questions
- Waiting & Synchronization4 questions
- Suite Maintenance4 questions
- UI-Level Case Design3 questions
- Framework Architecture55 questions
- AI-Augmented Testing28 questions
- Asynchronous Flows27 questions
- Mobile Test Design30 questions
- Notification Flows33 questions
- Test Data & Environments57 questions
- Sourcing Fixtures4 questions
- Builders & Object Mothers3 questions
- Isolation & Cleanup3 questions
- Staging Fidelity3 questions
- Service Virtualization4 questions
- Seeds & Locale Pinning4 questions
- Engine Substitutes4 questions
- Synthetic Data Generation12 questions
- Protecting Real Data20 questions
- Generated Test Cases13 questions
- Property-Based Testing5 questions
- Fuzzing4 questions
- Model-Based Testing4 questions
- Quality Practices & Metrics25 questions
- Effective Code Review4 questions
- Pairing & Ensemble Work4 questions
- Production Verification4 questions
- Suite & Pipeline Health5 questions
- Cost of Late Defects4 questions
- Quality Ownership Models4 questions
- Testing AI-Powered Features32 questions
- Case Design12 questions
- Suite Mechanics12 questions
- Release Judgement8 questions
- AI & Data Scientistroleanchors this topic
- AI Engineerroleanchors this topic
- Backend Developerroleanchors this topic
- Data Engineerroleanchors this topic
- Frontend Developerroleanchors this topic
- Full Stack Developerroleanchors this topic
- Game Developerroleanchors this topic
- Java Backend Developerroleanchors this topic
- Java SDETroleanchors this topic
- Kotlin Backend Developerroleanchors this topic
- MLOps Engineerroleanchors this topic
- Machine Learning Engineerroleanchors this topic
- QA Engineerroleanchors this topic
- Software Architectroleanchors this topic
- iOS Developerroleanchors this topic
- API Testingskill
- Git & GitHubskill
questions
651 · 13 sectionsWhat are the three phases of the Arrange-Act-Assert test structure?
basics
~20 sArrange builds the fixture, inputs and collaborators the test needs. Act invokes the one behaviour under test and captures its result. Assert compares that outcome with the expected one. Given-When-Then names the same three phases.
What is acceptance testing, and what decides whether a change passes it?
basics
~20 sAcceptance testing judges a change against the stated acceptance criteria of the requirement it implements, not against the shape of the code. It passes when every criterion is demonstrably met, and those criteria are agreed before the work starts.
What is an approval test, and how does it differ from a test with hand-written assertions?
basics
~20 sAn approval test runs the code, writes the output to a received artefact, and compares it against a previously approved artefact. Nobody types the expected value: a human reviews the output once and approves it, and the test then guards that exact output.
In boundary value analysis, which values do you test for a field that accepts 1 through 60?
basics
~20 sTest the edges, not the middle: 0 and 1 low, 60 and 61 high. Defects hide where a comparison flips from accept to reject, so each limit gets a value on it and one just past.
In a consumer-driven contract test, what does the recorded contract assert about the provider, and what does it deliberately not check?
basics
~20 sA consumer-driven contract records the requests one consumer sends and the response parts it actually reads, then asserts the provider can still produce them. It checks the shape of the boundary, not whether the provider's answers are correct.
What does "emergent design" mean in test-driven development, and where does the structure come from?
basics
~20 sEmergent design means the structure of the code is an output of the cycle, not a plan made before it. Each restructuring step reshapes working code, so the design arrives gradually instead of being guessed up front.
In TDD, what is the difference between outside-in and inside-out development?
basics
~20 sOutside-in TDD starts at an outer boundary and invents collaborator roles as they are needed, standing them in until they are built. Inside-out TDD starts with domain behaviour built from real objects and wires the outer layers in last.
Why must a test-driven test be watched failing before you write the code that passes it?
basics
~20 sWatching the test fail proves the assertion can actually detect the behavior's absence. A test that has never been red may be mis-wired, never executed, or trivially true, and would report green forever while guarding nothing.
Why run the test suite after each small refactoring move instead of once at the end?
basics
~20 sBecause a green run after every move tells you exactly which move changed behaviour. Run once at the end and a red suite only says something in the last hour was wrong, so you debug instead of undoing.
What is test-first development, and how does it differ from writing tests after the code?
basics
~20 sTest-first means writing an executable test for behaviour that does not exist yet, then writing code to satisfy it. Test-after writes tests against finished code, so the cases are shaped by what the code already does.
In double-loop TDD, what are the outer and inner loops, and which turns green last?
basics
~20 sThe outer loop is a failing acceptance scenario written in the user's language; the inner loop is the fast unit cycle beneath it. The inner loop goes green many times over; the outer scenario goes green last, when the behaviour is complete.
What is a step definition in a scenario suite, and what binds it to a line of a scenario?
basics
~20 sA step definition is a function holding the automation code for one scenario step. The runner matches the step's plain-language text against a pattern registered with that function, converts any captured values into arguments, and calls it.
What does a Background section in a feature file do to the scenarios below it?
basics
~10 sA Background holds context steps that run again before every scenario in that file, so shared setup is written once. Every scenario inherits those steps, whether or not it needs them.
In a behaviour scenario, what do the Given, When and Then steps each describe?
basics
~20 sGiven states the context that already holds before the behaviour under test. When names the single event that triggers it. Then states the observable outcome that must follow. All three describe behaviour, not interface mechanics.
What makes a scenario report generated from the last run 'living documentation'?
basics
~20 sThe document is generated from scenarios that actually executed, so it describes only behaviour the suite exercised. When the system changes and the scenario does not, the scenario fails and the page visibly breaks instead of quietly going stale.
What is a static-analysis baseline, and why create one when adopting an analyser on an existing codebase?
basics
~20 sA static-analysis baseline is a recorded snapshot of the findings an analyser already reports on existing code. The gate ignores those and fails only on findings outside the snapshot, so an old codebase can adopt analysis without a mass cleanup first.
Why run the same static analysis rule in the editor, at pre-commit, and in the build rather than only in the build?
basics
~20 sEach placement buys something different: the editor gives feedback in seconds while you type, the pre-commit check keeps a whole commit clean, and the build is the only placement that runs for everyone and can actually block a merge.
What is the difference between a formatting lint rule and a correctness lint rule?
basics
~20 sA formatting rule governs how code looks - spacing, indentation, ordering - and never changes behaviour. A correctness rule flags a shape that is likely a bug: a discarded return value, an unreachable branch, a resource never released.
In security static analysis, what are a source, a sink and a sanitizer in taint tracking?
basics
~20 sA source is where untrusted input enters the program, a sink is a sensitive operation that must not receive it, and a sanitizer neutralises the data. A finding is a source-to-sink path with no sanitizer on it.
What does a static type checker prove before a program runs, and which bugs does it never catch?
basics
~20 sA static type checker proves, without running the program, that every operation receives a value whose declared or inferred type it accepts. It rules out type-mismatch errors on all code paths, but says nothing about whether the logic is right.
What are entry criteria for a test cycle, and what do they prevent?
basics
~20 sEntry criteria are the conditions that must hold before a test cycle starts: a deployed build with a known change list, a healthy environment, seeded data, and agreed acceptance criteria. They prevent a cycle from burning its budget on setup failures.
What is the difference between verification and validation in a software lifecycle?
basics
~20 sVerification asks whether the product was built according to its specification. Validation asks whether that specification described the right thing to build. One checks conformance to a written statement, the other checks fitness for a real need.
In a test cycle status report, why is a blocked case counted separately from a failed one?
basics
~20 sA failed case ran and gave the wrong result, so it is evidence about the product. A blocked case never ran, because something stopped it. Merging the two hides untested scope and blames the product for an environment problem.
What is the difference between confirmation testing and regression testing after a defect fix?
basics
~20 sConfirmation testing re-runs the case that exposed the defect, to prove the fix works. Regression testing re-runs other cases around the change, to prove the fix broke nothing that previously passed. Both are needed after a fix.
What is risk-based test selection, and how do likelihood and impact rank what gets tested first?
basics
~20 sRisk-based test selection ranks each area by how likely it is to fail and how badly a failure would hurt, then spends the deepest testing on the highest-ranked areas and the least on the lowest.
What must a defect report contain for someone else to reproduce and fix it?
basics
~10 sAn unambiguous one-line title, the exact build identifier and environment, numbered preconditions and steps, the expected result and the actual result written separately, and evidence such as logs, screenshots or traces.
What is defect density, and why does the denominator you choose change the answer?
basics
~20 sDefect density is a count of confirmed defects divided by a size unit — a thousand lines of code, a functional size unit, a module, a feature. Change the unit and the same product scores differently.
What is the difference between a defect's origin phase and its escape phase?
basics
~20 sOrigin phase is where the defect was introduced - the requirement, design, code, data or configuration work that created it. Escape phase is the last check that should have caught it and did not. Every defect has both.
In a tracked defect's explanation, how do the symptom, the condition that produced it, and the weakness that let it reach a user differ?
basics
~20 sThe symptom is what was observed. The condition that produced it is the specific state or input that made the code fail that time. The weakness is the missing guard or assumption that allowed the whole family of failures.
What is the difference between a defect's severity and its priority?
basics
~20 sSeverity measures a defect's technical impact — how badly the product's behaviour breaks. Priority measures business urgency — how soon it should be fixed relative to other work. Different people set them, and the two values move independently.
How do you derive abuse and misuse cases from a documented happy-path flow?
basics
~20 sWalk each step of the happy path and ask what an actor could do instead: skip it, repeat it, reorder it, supply another actor's identifier, or exceed a limit. Each answer becomes a case the system must refuse.
What is volume testing, and how does it differ from a load test that raises request rate?
basics
~20 sVolume testing keeps the request rate fixed and grows the stored dataset instead: more rows, longer collections, larger files. It exposes defects that appear only at size, such as unbounded queries, memory that scales with result size, and jobs that outgrow their window.
What is the difference between an internationalization defect and a translation defect?
basics
~20 sAn internationalization defect is in the product code: a string that was never extracted, a hardcoded date format, a container that cannot hold a longer word. A translation defect is in the text itself, wrong or missing wording.
In a performance run, what are ramp-up, steady state and warm-up, and which window do you measure?
basics
~20 sRamp-up is the stretch while offered load climbs to the target level; steady state is where that load is held constant; warm-up is the early portion where caches, pools and compiled code settle. Report the steady state only.
What is a support matrix in compatibility testing, and what does one cell of it commit you to?
basics
~20 sA support matrix is the published grid of platform combinations — operating system, version, engine, device class — where a product promises to work. Each listed cell is a commitment: a defect that reproduces there is one you owe a fix.
Why narrow a defect to the shortest reliable reproduction before you report it?
basics
~20 sA short reproduction proves which conditions actually cause the failure. Every step you can delete without losing the failure is noise that slows diagnosis, invites a cannot-reproduce close, and hides the real trigger from whoever has to fix it.
What is a bug bash and who takes part in one?
basics
~20 sA bug bash is a short, time-boxed event where many people — developers, support, product and testers — hunt defects in one shared build at once, each covering an assigned area and filing into one channel.
What is a test charter in exploratory testing, and what does its three-part shape name?
basics
~20 sA test charter is a one- or two-sentence mission for a single exploratory session. The common shape names three things: what to explore, what to explore it with, and what information the session should discover.
What is a test oracle, and what makes one fallible?
basics
~20 sA test oracle is whatever you use to decide that an observed behaviour is wrong: a written specification, a standard, a comparable product, an earlier version, or your own expectation. Each is an imperfect model, so it can be wrong too.
What is a timeboxed test session in session-based test management?
basics
~20 sA session is one uninterrupted block of testing, commonly 60, 90 or 120 minutes, spent on a single charter and written up as one reviewable record. The session, not the test case, is the unit of work you plan and count.
Machine-drafted cases triple a regression suite's case count in a week. What has that growth not proven?
basics
~20 sCase count measures how much was written, not how much can be detected. Drafted cases usually re-walk journeys existing cases already walk and check outcomes already checked, so the set of failures the suite can catch may not grow.
When a suite repairs its own broken locators and still passes, which product defects does that green run hide?
basics
~20 sA repair hides every change that broke the original anchor: a control that moved, was relabelled, lost its announced name, or was replaced by a different one. The suite reports the flow works while the interface changed.
What should a service-interface test assert about a response instead of comparing the whole payload?
basics
~20 sAssert the status code, the few fields the case is actually about, and the response shape the contract promises — and on failure paths the error envelope's code. Whole-body equality breaks whenever an unrelated field changes.
How does an automated case observe an outbound callback that the system sends to a configured destination?
basics
~20 sPoint the system's configured destination at a receiver the run stands up, then read the recorded request back from it. The receiver must be reachable from where the system runs, not only from the machine running the suite.
Which property should an automated test assert on when the effect it checks lands only after the call returns?
basics
~20 sAssert on a settled invariant, a property that stays true once the flow has finished, such as a terminal status or a final total. Do not assert on a counter or an intermediate status that is true for only a moment.
What is the difference between an object mother and a test-data builder?
basics
~20 sAn object mother exposes named ready-made instances, so a test asks for a case by name. A test-data builder starts from valid defaults and lets a test override only the fields that case depends on.
Why do test suites run against an in-memory database stand-in, and what does that hide?
basics
~20 sAn in-memory database stand-in starts in milliseconds, needs no external service and resets cleanly between cases, so a suite runs fast anywhere. It hides every behaviour where the production engine differs: dialect, type coercion, collation, constraint enforcement and locking.
How do hand-built fixtures, generated records and production extracts differ as test-data sources?
basics
~20 sHand-built fixtures state only the few records a case needs, so they read clearly and carry no privacy risk. Generated records buy volume and variety cheaply. Production-derived extracts show real shapes and skew, but must be cut down and masked first.
Why must a test's teardown still run after an assertion fails partway through the test?
basics
~20 sA failing assertion aborts the test body, so cleanup written after it never executes and the records it created leak into later tests. Register teardown as an after-each hook or a resource-scoped block so it runs on both exits.
Why should a test that generates random data record and print the seed it used?
basics
~20 sRandom data makes a failure depend on values nobody chose. Recording the seed and printing it in the failure output lets anyone re-run the identical values, so the failure can be reproduced and fixed instead of guessed at.
What is fuzzing, and what counts as a failure when there is no expected output to compare against?
basics
~20 sFuzzing drives a program with large volumes of generated, malformed or mutated input. Because no per-input expected result exists, the oracle is the program's own bad behaviour: crashes, hangs, assertion failures, and reports from an instrumented build.
What is model-based testing, and where do the executable test cases come from?
basics
~20 sModel-based testing builds an explicit model of intended behaviour, usually a state machine, and derives cases from it automatically. A generator walks paths through the model; each walk becomes a test, and the model predicts the expected result.
What is a round-trip property in property-based testing, and what bug can it miss?
basics
~20 sA round-trip property asserts that transforming a value and then reversing the transformation returns the original value, for every generated input. It misses paired defects: when both directions are wrong in mirror-image ways, the trip still returns the input unchanged.
How do dumb mutation, grammar-aware generation and coverage-guided fuzzing differ, and when is each right?
basics
~20 sDumb mutation flips bytes in existing inputs and knows nothing about the format. Grammar-aware generation builds well-formed inputs from a description of the format. Coverage-guided fuzzing uses an instrumented build to keep inputs that reach new code and mutate those further.
How do you state a property for a function that has no inverse to round-trip against?
basics
~10 sAssert a rule the output must satisfy rather than a specific value: an invariant or postcondition, idempotence, agreement with a simpler reference implementation, or a metamorphic relation between two runs on related inputs.
In what order should you read a code change under review, and why does the order matter?
basics
~20 sRead the intent first — what problem the change claims to solve — then the contract it exposes, then the edge cases and error paths, then the tests. That order settles whether the change is right before you argue about how it is written.
Why does a defect found in production usually cost more to fix than the same defect found during development?
basics
~20 sA production defect costs more because the code change is only a fraction of the work. Someone must notice it, reproduce it and re-learn code written weeks ago, and the team then pays for data repair, support and an unplanned release.
What are the common quality ownership models, from an independent test group to whole-team quality?
basics
~20 sFour shapes recur: an independent test group that verifies finished work, testers embedded in each delivery team, whole-team quality where every engineer tests and no dedicated tester exists, and a small coaching group that builds testing skill in others.
How do you measure a test suite's flake rate, and why is its trend more useful than its level?
basics
~20 sFlake rate is the share of runs or cases giving a different verdict on the same unchanged revision. Measure it by recording every attempt, not just the final one, and track the trend: an acceptable level depends on suite size.
A feature's answer text comes from a generative step. In what distinct ways can that step fail to deliver an answer?
basics
~20 sFour delivery failures matter: nothing comes back inside the deadline, the call is refused for volume, the provider is unavailable, or the input exceeds what the step accepts. Each strands the user differently, so each earns its own test case.
For a feature whose answer text comes from a generative step, what makes an acceptance criterion adjudicable?
basics
~20 sAn adjudicable acceptance criterion names one observable property of the response, says where to look for it, and fixes the decision rule in advance, so two testers reading the same response record the same pass or fail.
Before writing test cases for an AI-powered feature, why agree how often each acceptance criterion may miss?
basics
~20 sA criterion with no stated allowance is read as absolute, so the first response that misses it forces an unplanned argument. Agreeing the allowance up front makes a rare miss an expected, recorded outcome rather than a crisis.
When a test of a feature that answers from a generative step fails and will not reproduce, what must that test run itself have recorded?
basics
~20 sWrite the evidence at failure time, because a repeat may never reproduce it: the exact input, the material and instruction text given to the generative step, the model identifier and generation settings, the raw output, and a correlation id.
Which layers can own a wrong answer from an AI-powered product feature, and how do you decide which one it is?
basics
~20 sFive layers can own it: the ordinary product code around the generative step, the instruction text sent to it, the material supplied with it, the configuration, and the generative model's own capability ceiling. Attribute only after evidence separates them.