cs3002_2026T2_Q1_NA.pdf
Software Testing · Quiz 1 · May 2026
← Course papers · Start practice / exam
Questions and published explanations below are available without starting a test. Some questions may not have a published solution yet.
Question 2 MCQ · 5.0 marks
In an organization, software teams understand that the objective of testing is to reduce risks. Due
to this, the developers and testers are cooperating with each other to help fix issues and reduce
risks. Considering this scenario, identify the minimum process maturity level of this organization.
Level 1
Level 2
Level 3
Level 4
Published solution
**1. Understand / Given:** The team believes the objective of testing is to *reduce risk*, and developers and testers cooperate to fix issues.
**2. Apply the concept:** Beizer's testing maturity levels are:
- Level 0: testing = debugging
- Level 1: testing shows the software works
- Level 2: testing shows the software does not work
- Level 3: testing reduces risk
- Level 4: testing is a mental discipline that improves quality
**3. Conclude:** Reducing risk with cooperating developers and testers is the Level 3 mindset.
Answer: C — Level 3.
A: **Incorrect:** Level 1 means 'show that the software works'. Risk reduction is not its goal.
B: **Incorrect:** Level 2 means 'find failures'. It does not yet talk about reducing risk.
C: **Correct:** This matches the description: testing aims to reduce risk and teams cooperate.
D: **Incorrect:** Level 4 is a quality-improving mental discipline, which goes beyond the scenario.
Question 3 MCQ · 5.0 marks
An e-commerce application contains separate modules for user authentication, shopping cart
management, and payment processing.Although each module behaves correctly in isolation, the
engineering team discovers issues when customer login sessions are transferred incorrectly
between modules during checkout.
Which of the following types of testing is primarily intended to identify such problems?
Stress testing
Integration testing
Regression testing
Usability testing
Published solution
**1. Understand / Given:** Each module (authentication, cart, payment) works correctly alone. The fault appears only when login session data passes from one module to another.
**2. Apply the concept:** Faults in the *interaction between modules* (interfaces and data passing) are found by integration testing.
**3. Conclude:** The problem is an interface problem between modules, so integration testing is the right type.
Answer: B — Integration testing.
A: **Incorrect:** Stress testing checks behaviour under extreme load, not wrong data passing between modules.
B: **Correct:** Integration testing targets faults at module interfaces, such as session data transferred incorrectly.
C: **Incorrect:** Regression testing re-checks old behaviour after changes. It is not aimed at module interface faults.
D: **Incorrect:** Usability testing checks ease of use for users, not internal data transfer.
Question 4 MCQ · 5.0 marks
Consider the following statements and choose the correct option.
i) In JUnit, each test is embedded into one test method.
ii) The assertion [[IMAGE:6cf9c79bdc0808ef_3_2]] would fail.

Statement i) is correct and Statement ii) is incorrect.
Statement ii) is correct and Statement i) is incorrect.
Both statements are incorrect.
Both statements are correct.
Published solution
**1. Statement i):** In JUnit, each test case is written as one test method (a method annotated with \(@Test\)). So statement i) is correct.
**2. Statement ii):** Evaluate the condition:
\[5 \% 2 = 1,\quad 1 == 0 \Rightarrow \text{false}\]
\(assertFalse(\text{false})\) passes, so the assertion does **not** fail. Statement ii) is incorrect.
**3. Conclude:** i) is correct and ii) is incorrect.
Answer: A — Statement i) is correct and Statement ii) is incorrect.
A: **Correct:** Statement i) is true, and ii) is false because the assertion passes.
B: **Incorrect:** Statement ii) is wrong: 5 % 2 == 0 is false, so assertFalse passes.
C: **Incorrect:** Statement i) is true, so 'both incorrect' is wrong.
D: **Incorrect:** Statement ii) is false, so 'both correct' is wrong.
Question 5 MCQ · 5.0 marks
A ____________ is a software component or test tool that replaces a component that takes care of
the control and/or the calling of a software component.
Fill in the blank with correct option.
test method
test suite
test driver
test stub
Published solution
**1. Understand / Given:** The blank describes a component that *replaces the caller/controller* of the component under test.
**2. Apply the concept:** A **test driver** calls the component under test and controls it. A **test stub** is the opposite: it replaces a component that is *called by* the software under test.
**3. Conclude:** The description matches a test driver.
Answer: C — test driver.
A: **Incorrect:** A test method is one JUnit test case. It is not a replacement component.
B: **Incorrect:** A test suite is a collection of tests, not a replacement component.
C: **Correct:** A driver replaces the caller or controller and invokes the component under test.
D: **Incorrect:** A stub replaces a called component, not the calling or controlling one.
Question 6 MCQ · 5.0 marks
A user is browsing a website. She types a query in a text box and clicks on Search. Upon clicking
the Search button, a request is made to the server which then retrieves the relevant items and
returns a response. Which of the following types of interfaces does this scenario represent?
Procedure call interface
Shared memory interface
External file interface
Message passing interface
Published solution
**1. Understand / Given:** A browser sends a request to a server, and the server sends a response back.
**2. Apply the concept:** Interfaces can be procedure call, shared memory, message passing, or external file. When separate components exchange explicit request and response messages, it is a message passing interface.
**3. Conclude:** The client–server request/response is message passing.
Answer: D — Message passing interface.
A: **Incorrect:** Procedure call interface means one component directly calls another's procedure in the same program. Not the case here.
B: **Incorrect:** Shared memory means both sides read and write a common memory area. Not described here.
C: **Incorrect:** External file interface exchanges data through files. Not described here.
D: **Correct:** The client sends a request message and the server returns a response message.
Question 7 MCQ · 5.0 marks
Consider the following statements regarding structural graph coverage criteria, and choose the
correct option.
i) Prime path coverage always subsumes edge-pair coverage.
ii) A prime path is also a simple path.
iii) Complete path coverage may be feasible for some CFGs.
Statement i) and iii) are correct. Statement ii) is incorrect.
Statement ii) and iii) are correct. Statement i) is incorrect.
Statement i) and ii) are correct. Statement iii) is incorrect.
Statement i) is correct. Statement ii) and iii) are incorrect.
Published solution
**1. Statement i):** The word *always* makes this false. Prime path coverage (PPC) does not always subsume edge-pair coverage. Example: a node \(b\) with a self-loop \(b\to b\). Edge pair \((b,b,b)\) needs the loop to be traversed twice, but PPC only requires the prime path \([b,b]\) once. So i) is incorrect.
**2. Statement ii):** A prime path is, by definition, a simple path that is not a proper subpath of any other simple path. So every prime path is a simple path. ii) is correct.
**3. Statement iii):** Complete path coverage needs all paths. For a loop-free (acyclic) CFG the number of paths is finite, so it can be feasible. iii) is correct.
**4. Conclude:** ii) and iii) are correct, i) is incorrect.
Answer: B — Statement ii) and iii) are correct. Statement i) is incorrect.
A: **Incorrect:** it marks i) as correct, but PPC does not always subsume edge-pair coverage.
B: **Correct:** ii) and iii) are true, and i) is false.
C: **Incorrect:** it marks iii) as incorrect, but acyclic CFGs have finitely many paths.
D: **Incorrect:** it marks ii) and iii) as incorrect, but both are true.
Question 8 MCQ · 5.0 marks
Consider a control flow graph [[IMAGE:6cf9c79bdc0808ef_4_3]] . In which of the following types of testing, the number of test
requirements (TRs) is equal to the cyclomatic complexity of [[IMAGE:6cf9c79bdc0808ef_4_4]] ?


Basis Path Testing
Prime Path Coverage
Data Flow Testing
Edge-Pair Coverage
Published solution
**1. Understand / Given:** We need the testing type whose number of test requirements equals the cyclomatic complexity \(V(G)\).
**2. Apply the concept:** Basis path testing finds a *basis set* of independent paths. The size of this set is exactly \(V(G)=E-N+2P\). Prime path, data flow, and edge-pair coverage have requirement counts that depend on other graph features.
**3. Conclude:** Basis path testing.
Answer: A — Basis Path Testing.
A: **Correct:** The number of basis paths equals the cyclomatic complexity.
B: **Incorrect:** Prime paths are maximal simple paths. Their count is not tied to \(V(G)\).
C: **Incorrect:** Data flow TRs depend on definition–use pairs, not on \(V(G)\).
D: **Incorrect:** Edge-pair TRs depend on pairs of consecutive edges, not on \(V(G)\).
Question 9 MCQ · 5.0 marks
Which of the following models is best to capture state behavior when testing sequencing
constraints of a program or module?
Activity Diagrams
Control Flow Graphs (CFGs)
Finite State Machines (FSMs)
Call Graphs
Published solution
**1. Key concept:** Sequencing constraints (which operation is allowed after which, in what state) are *state-based* behaviour.
**2. Apply:** A Finite State Machine models states and transitions triggered by events, so it captures allowed sequences directly. CFGs model code control flow, call graphs model who calls whom, and activity diagrams model workflow activities.
**3. Conclude:** FSMs.
Answer: C — Finite State Machines (FSMs).
A: **Incorrect:** Activity diagrams show workflows and activities, not state behaviour.
B: **Incorrect:** CFGs show control flow inside code, not state behaviour.
C: **Correct:** FSMs model states and transitions, so they capture sequencing constraints.
D: **Incorrect:** Call graphs show calling relations between methods, not state behaviour.
Question 10 MCQ · 5.0 marks
Which of the following graph coverage criteria is equivalent to transition coverage on a finite state
machine (FSM)?
Node coverage
Edge coverage
Edge-pair coverage
Prime path coverage
Published solution
**1. Understand / Given:** In an FSM, states are nodes and transitions are edges.
**2. Apply:** Transition coverage means every transition is taken at least once. Taking every transition is exactly covering every edge of the graph.
**3. Conclude:** Transition coverage is equivalent to edge coverage.
Answer: B — Edge coverage.
A: **Incorrect:** Node coverage visits every state, but it does not force every transition to be taken.
B: **Correct:** Transitions are edges, so covering every transition is edge coverage.
C: **Incorrect:** Edge-pair coverage needs sequences of two consecutive transitions, which is stronger.
D: **Incorrect:** Prime path coverage is much stronger than just covering each transition.
Question 11 MCQ · 5.0 marks
Which of the following options correctly describes All-Uses Coverage criterion for a variable [[IMAGE:6cf9c79bdc0808ef_5_5]] ?

At least one definition of [[IMAGE:6cf9c79bdc0808ef_5_6]] must reach at least one use.

Each definition of [[IMAGE:6cf9c79bdc0808ef_5_7]] must reach at least one possible use.

At least one definition of [[IMAGE:6cf9c79bdc0808ef_5_8]] must reach every possible use.

Each definition of [[IMAGE:6cf9c79bdc0808ef_5_9]] must reach every possible use.

Published solution
**1. Understand / Given:** All-Uses coverage is a data flow criterion for variable \(x\).
**2. Apply the concept:** All-Uses requires, for each definition of \(x\), a def-clear path to *every* use (c-uses and p-uses) that the definition can reach. All-Defs is weaker: each definition must reach *at least one* use.
**3. Conclude:** Each definition of \(x\) must reach every possible use.
Answer: D — Each definition of \(x\) must reach every possible use.
A: **Incorrect:** Only one definition reaching one use is weaker than All-Defs, so it is not All-Uses.
B: **Incorrect:** This is the All-Defs criterion, not All-Uses.
C: **Incorrect:** Covering every use from only one definition is not required. Each definition must be considered.
D: **Correct:** This matches All-Uses: every definition must reach every use it can reach.
Question 12 MSQ · 5.0 marks
Which of the following statements are correct regarding the representation of graphs?
Adjacency list representation provides a compact way to represent sparse
graphs.
Adjacency matrix representation cannot be used for control flow graphs.
Adjacency list representation cannot be used for control flow graphs.
Adjacency matrix representation provides a compact way to represent dense
graphs.
Published solution
**1. Adjacency list:** It stores only the existing edges of each vertex, so it uses little memory for sparse graphs. Option A is correct.
**2. Adjacency matrix:** It uses an \(n\times n\) table. This is wasteful for sparse graphs but compact enough for dense graphs, where most entries are used. Option D is correct.
**3. Control flow graphs:** A CFG is a directed graph, so it can be stored with either an adjacency matrix or an adjacency list. Options B and C are false.
**4. Conclude:** A and D are correct.
Answer: A, D — Adjacency list is compact for sparse graphs; adjacency matrix is compact for dense graphs.
A: **Correct:** Only existing edges are stored, so it is compact for sparse graphs.
B: **Incorrect:** A CFG is a directed graph and can be stored as an adjacency matrix.
C: **Incorrect:** A CFG can also be stored as an adjacency list.
D: **Correct:** Matrix space is \(n^2\), which is efficient when the graph is dense.
Question 13 MSQ · 5.0 marks
Which of the following types of testing methods are black box, i.e. those that do not require
knowledge about the internals of the program?
Integration Testing
Unit Testing
Beta Testing
Stress Testing
Published solution
**1. Understand / Given:** Black-box methods use only inputs and outputs/behaviour, not the code internals.
**2. Evaluate each type:**
- Beta testing: real users try the product without code knowledge, so black box.
- Stress testing: the system is loaded beyond normal limits and observed externally, so black box.
- Unit testing: tests code units and normally uses knowledge of the code, so not black box.
- Integration testing: tests module interfaces using design/code knowledge, so not black box.
**3. Conclude:** Beta Testing and Stress Testing.
Answer: C, D — Beta Testing and Stress Testing.
A: **Incorrect:** Integration testing relies on knowledge of module interfaces and internals.
B: **Incorrect:** Unit testing is normally done with knowledge of the code of the unit.
C: **Correct:** Beta testing is done by users with no knowledge of the internals.
D: **Correct:** Stress testing observes behaviour under extreme load from outside.
Question 14 MSQ · 5.0 marks
Which of the following statements are true regarding a decision-to-decision (DD) path?
Every chain is also a valid DD-path.
It can be a single vertex with out-degree [[IMAGE:6cf9c79bdc0808ef_6_10]] .

It cannot consist of only the final vertex.
It can consist of only the initial vertex.
Published solution
**1. Concept:** In a decision-to-decision (DD) path graph, a DD-path is one of: (a) a single vertex with in-degree 0 (initial), (b) a single vertex with out-degree 0 (final), (c) a single vertex with in-degree \(\ge 2\) or out-degree \(\ge 2\), (d) a single vertex with in-degree 1 and out-degree 1, (e) a *maximal* chain of length \(\ge 1\).
**2. Check options:**
- A: Only *maximal* chains are DD-paths, so not every chain is valid. False.
- B: A single vertex with out-degree \(\ge 2\) is a DD-path (case c). True.
- C: The final vertex alone is a DD-path (case b). So the statement is False.
- D: The initial vertex alone is a DD-path (case a). True.
**3. Conclude:** B and D are true.
Answer: B, D — B and D are true.
A: **Incorrect:** Only maximal chains are DD-paths, so not every chain qualifies.
B: **Correct:** A single vertex with out-degree at least 2 is a valid DD-path.
C: **Incorrect:** The final vertex alone is a valid DD-path, so this statement is false.
D: **Correct:** The initial vertex alone is a valid DD-path.
Question 15 MSQ · 5.0 marks
Consider the following Java code for [[IMAGE:6cf9c79bdc0808ef_6_11]] class, there are some faults in it. The method
[[IMAGE:6cf9c79bdc0808ef_6_12]] needs to be
tested using the JUnit test class [[IMAGE:6cf9c79bdc0808ef_6_13]] .
[[IMAGE:6cf9c79bdc0808ef_7_14]]
Identify which of the test cases would be able to uncover the faults in the program.




[[IMAGE:6cf9c79bdc0808ef_7_15]]

[[IMAGE:6cf9c79bdc0808ef_7_16]]

[[IMAGE:6cf9c79bdc0808ef_7_17]]

[[IMAGE:6cf9c79bdc0808ef_8_18]]

Published solution
**1. Find the fault:** The loop is `for (int i = 0; i < arr.length - 1; i++)`. It stops one element early, so the **last element is never added**. The correct condition is `i < arr.length`.
**2. Run each test with the faulty code:**
- testCase1: \(\{2,3,4,5\}\) gives \(2+3+4=9\), expected 14. Fails, so it exposes the fault.
- testCase2: \(\{10,20,-5,-1\}\) gives \(10+20=30\), expected 30. Passes, because the skipped last element is negative.
- testCase3: \(\{-1,-2,-3,0\}\) gives 0, expected 0. Passes, because the skipped last element is 0.
- testCase4: \(\{-4,-2,8,10\}\) gives \(8\), expected 18. Fails, so it exposes the fault.
**3. Conclude:** Only test cases whose last element is positive reveal the fault: testCase1 and testCase4.
Answer: A, D — testCase1() and testCase4().
A: **Correct:** The last element 5 is skipped, so the result is 9 instead of 14 and the test fails.
B: **Incorrect:** The skipped last element is negative, so the sum is unchanged and the test passes.
C: **Incorrect:** The skipped last element is 0, so the sum is unchanged and the test passes.
D: **Correct:** The last element 10 is skipped, so the result is 8 instead of 18 and the test fails.
Question 16 MCQ · 5.0 marks
Consider the following control flow graph (CFG), and answer the subsequent questions.
[[IMAGE:6cf9c79bdc0808ef_8_19]]
How many test requirements are there for edge-pair coverage?

8
11
7
9
Published solution
**1. Given:** The CFG has edges \(1\to2,\ 1\to3,\ 2\to4,\ 2\to6,\ 4\to5,\ 5\to4,\ 3\to7,\ 6\to7\). Node 1 is the initial node and node 7 is final.
**2. Concept:** Edge-pair coverage needs every path of length 2 (two consecutive edges), i.e. each (incoming edge, outgoing edge) pair at a node.
**3. List them:**
- Through node 2: \([1,2,4]\), \([1,2,6]\)
- Through node 3: \([1,3,7]\)
- Through node 4: \([2,4,5]\), \([5,4,5]\)
- Through node 5: \([4,5,4]\)
- Through node 6: \([2,6,7]\)
Count: \(2+1+2+1+1=7\).
**4. Conclude:** There are 7 test requirements.
Answer: C — 7.
A: **Incorrect:** Only 7 edge pairs exist, not 8.
B: **Incorrect:** Only 7 edge pairs exist, not 11.
C: **Correct:** Counting pairs at nodes 2, 3, 4, 5 and 6 gives 2+1+2+1+1 = 7.
D: **Incorrect:** Only 7 edge pairs exist, not 9.
Question 17 MCQ · 5.0 marks
Consider the following control flow graph (CFG), and answer the subsequent questions.
[[IMAGE:6cf9c79bdc0808ef_8_19]]
How many test requirements are there for prime path coverage?

9
12
7
5
Published solution
**1. Concept:** A prime path is a simple path (no repeated node, except the first may equal the last) that is not a proper subpath of any other simple path.
**2. Find maximal simple paths:**
- \([1,2,4,5]\) (cannot be extended: \(5\to4\) would repeat 4)
- \([1,2,6,7]\)
- \([1,3,7]\)
- \([4,5,4]\) (cycle)
- \([5,4,5]\) (cycle)
**3. Check:** Other simple paths like \([2,4,5]\), \([4,5]\), \([2,6,7]\) are subpaths of these, so they are not prime.
**4. Conclude:** There are 5 prime paths.
Answer: D — 5.
A: **Incorrect:** Only 5 maximal simple paths exist, not 9.
B: **Incorrect:** Only 5 maximal simple paths exist, not 12.
C: **Incorrect:** Only 5 maximal simple paths exist, not 7. Seven is the number of edge pairs.
D: **Correct:** The prime paths are [1,2,4,5], [1,2,6,7], [1,3,7], [4,5,4] and [5,4,5].
Question 18 MCQ · 5.0 marks
Consider the following control flow graph (CFG), and answer the subsequent questions.
[[IMAGE:6cf9c79bdc0808ef_8_19]]
What is the cyclomatic complexity of the given CFG?

3
4
5
6
Published solution
**1. Given:** Edges \(E=8\), nodes \(N=7\), connected components \(P=1\).
**2. Formula:** \(V(G)=E-N+2P\).
**3. Substitute:**
\[V(G)=8-7+2(1)=3\]
**4. Conclude:** The cyclomatic complexity is 3.
Answer: A — 3.
A: **Correct:** E - N + 2 = 8 - 7 + 2 = 3.
B: **Incorrect:** The formula gives 3, not 4.
C: **Incorrect:** The formula gives 3, not 5.
D: **Incorrect:** The formula gives 3, not 6.
Question 19 MCQ · 5.0 marks
Consider the following data flow graph, and answer the subsequent questions.
[[IMAGE:6cf9c79bdc0808ef_9_20]]
How many test requirements are there for All-Defs-Coverage for variable [[IMAGE:6cf9c79bdc0808ef_9_21]] ?


4
2
3
1
Published solution
**1. Given:** In the graph, \(x\) is defined at node 1 (\(x=a\)) and at node 4 (\(x=z\)).
**2. Concept:** All-Defs coverage needs, for each definition of \(x\), one def-clear path to at least one use. So one test requirement per definition.
**3. Count:** Two definitions (nodes 1 and 4) give 2 requirements.
**4. Conclude:** 2 test requirements.
Answer: B — 2.
A: **Incorrect:** There are only 2 definitions of x, so 4 is too many.
B: **Correct:** One requirement for each of the 2 definitions (nodes 1 and 4).
C: **Incorrect:** There are only 2 definitions of x, not 3.
D: **Incorrect:** There are 2 definitions, so 1 is too few.
Question 20 MCQ · 5.0 marks
Consider the following data flow graph, and answer the subsequent questions.
[[IMAGE:6cf9c79bdc0808ef_9_20]]
How many test requirements are there for All-Uses-Coverage for variable [[IMAGE:6cf9c79bdc0808ef_10_22]] ?


4
6
5
7
A published solution is not available for this question yet.
Question 21 MCQ · 5.0 marks
Consider the following data flow graph, and answer the subsequent questions.
[[IMAGE:6cf9c79bdc0808ef_9_20]]
How many unique du-paths are there for variable [[IMAGE:6cf9c79bdc0808ef_10_23]] ?
Note: Do not consider subsumption for the du-paths.


7
6
9
8
A published solution is not available for this question yet.