NivaarExam PrepOfficial exam papers ↗

19-Soft-A6 Software Quality Assurance · December 2013

Question 5 of 8: Black-Box Test of an Access-Control Unit

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams, December 2013 — 04-Soft-A6, Software Quality Assurance (open book, non-communicating calculator permitted, 3 hours). Per the paper's own notes, FIVE of the EIGHT questions constitute a complete exam and each is of equal value; all eight are answered in full below as a complete study resource.

Reference texts. Pressman, Software Engineering: A Practitioner's Approach, 9th ed., Ch. 15 (SQA), Ch. 17–18 (unit/integration/validation/system testing strategy), Ch. 19–20 (white-box basis-path testing, black-box equivalence partitioning & boundary value analysis); Sommerville, Software Engineering, 10th ed., Ch. 8 (Software Testing) and Ch. 24 (Quality Management); SWEBOK v4, Software Quality KA and Software Testing KA; ISO/IEC 25010 (SQuaRE) for the software product quality model referenced in Question 1; ISO/IEC/IEEE 12207 (Software life cycle processes) for the process-standard referenced in Question 1(b).

Question 5: Black-Box Test of an Access-Control Unit (10 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

Given. Username: 4–8 characters, must exist in the system database. Password: 8–10 characters, must contain at least one capital letter, one digit, and one special character.

Find. A black-box test-case set (equivalence partitioning + boundary value analysis) that exercises every valid and invalid class of both fields, including the character-composition conditions on the password, without reference to the unit's internal code.

Approach. Apply the range guideline from Question 4(b) to each field's LENGTH condition (one valid class, two invalid classes, tested additionally at all four boundary points), and partition the password's three composition requirements as three independent single-condition checks — standard black-box practice for input governed by several ANDed conditions is to violate exactly ONE condition per test case while holding the others valid, so a failure can be attributed to a specific condition rather than a confounded combination.

  1. Partition the username field. Length is a range condition (4–8): valid class VU1 = length in [4,8] AND present in the database; invalid classes VU2 = length < 4 (too short), VU3 = length > 8 (too long), VU4 = length in [4,8] but NOT present in the database (a fourth invalid class specific to the "in the database" clause, beyond the pure length range). Boundary points for the length range: $3, 4, 8, 9$ (one below the minimum, the minimum itself, the maximum itself, one above the maximum).
  2. Partition the password field. Length is a range condition (8–10): valid class VP1 = length in [8,10] with all three composition rules satisfied; invalid classes for length alone: VP2 = length < 8, VP3 = length > 10. Boundary points: $7, 8, 10, 11$. Composition is three further Boolean-style conditions, each contributing one more invalid class when violated alone: VP4 = correct length, no uppercase letter; VP5 = correct length, no digit; VP6 = correct length, no special character.
  3. Assemble the test-case table. One representative value per class, plus the four boundary lengths on each field, holding the OTHER field valid in every row so a failure is attributable to the row's own field/condition.
#UsernamePasswordCondition under testExpected result
TC1bsmith (6 ch., in DB)Passw0rd! (9 ch.)VU1 & VP1 — both fields fully validAccess granted
TC2bob (3 ch.)Passw0rd!VU2 / boundary 3 — below minimum lengthRejected: username too short
TC3alex (4 ch., in DB)Passw0rd!Boundary 4 — minimum valid lengthAccepted (username field)
TC4bsmith01 (8 ch., in DB)Passw0rd!Boundary 8 — maximum valid lengthAccepted (username field)
TC5bsmith012 (9 ch.)Passw0rd!VU3 / boundary 9 — above maximum lengthRejected: username too long
TC6zqxvwt (6 ch., not in DB)Passw0rd!VU4 — correct length, unregisteredRejected: unknown username
TC7bsmithPw0!xyz (7 ch.)VP2 / boundary 7 — below minimum lengthRejected: password too short
TC8bsmithPassw0r! (8 ch.)Boundary 8 — minimum valid lengthAccepted (password field)
TC9bsmithPassw0rd12! (10 ch.)Boundary 10 — maximum valid lengthAccepted (password field)
TC10bsmithPassw0rd123! (11 ch.)VP3 / boundary 11 — above maximum lengthRejected: password too long
TC11bsmithpassword1! (9 ch., no capital)VP4 — missing uppercase letterRejected: needs one capital letter
TC12bsmithPasssword! (10 ch., no digit)VP5 — missing digitRejected: needs one number
TC13bsmithPassword12 (10 ch., no special char.)VP6 — missing special characterRejected: needs one special character