NivaarExam PrepOfficial exam papers ↗

19-Soft-A6 Software Quality Assurance · May 2016

Question 7 of 8

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

04-Soft-A6, Software Quality Assurance — National Exams, May 2016 (3 hours, open book, 8 questions of equal value; the first FIVE as they appear in the answer book are marked — all eight are solved here as a study resource).

Reference texts: Pressman, Software Engineering: A Practitioner's Approach, 9th ed. (SQA planning, review, testing strategies/techniques, cyclomatic complexity, basis path testing); Sommerville, Software Engineering, 10th ed. (software process, agile practice, configuration management); ISO/IEC 25010 SQuaRE (software quality characteristics); ISO/IEC 12207 (life-cycle/configuration-management processes).

Question 7 (10 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

Given. The authentication subsystem's declared interface constraints (the specification, not the implementation): login length ∈ [6, 8] characters; password length ∈ [6, 8] characters AND must contain at least one lower-case letter, at least one upper-case letter, and at least one digit.

Find. A black-box test suite, derived purely from these stated constraints, that exercises every equivalence class and every length boundary for both the login and the password fields.

Approach. Apply equivalence partitioning to the length constraint (too-short / valid / too-long, for both fields) and to the password's three required character classes (missing lower-case / missing upper-case / missing digit), then apply boundary value analysis to the length limits (exactly 6, exactly 8, one below, one above).

  1. Test case 1 — valid baseline (both fields valid, all password classes present). Login alice1 (6 chars), password Abc123 (6 chars, has lower/upper/digit).
    login = "alice1", password = "Abc123"
    Expected result: accepted — the reference case every other test case is compared against.
  2. Test case 2 — login too short. Login equivalence class: length < 6.
    login = "bob" (3 chars), password = "Xyz789"
    Expected result: rejected — login shorter than the 6-character minimum.
  3. Test case 3 — login too long. Login equivalence class: length > 8.
    login = "alice123456" (11 chars), password = "Xyz789"
    Expected result: rejected — login longer than the 8-character maximum.
  4. Test case 4 — login at the lower length boundary (BVA). Login exactly 6 characters, the declared minimum.
    login = "abcdef" (6 chars), password = "Ab1defg"
    Expected result: accepted — 6 is exactly the boundary, not below it.
  5. Test case 5 — login at the upper length boundary (BVA). Login exactly 8 characters, the declared maximum.
    login = "abcdefgh" (8 chars), password = "Ab1defgh"
    Expected result: accepted — 8 is exactly the boundary, not beyond it.
  6. Test case 6 — password too short. Password equivalence class: length < 6.
    login = "carol1", password = "Ab1de" (5 chars)
    Expected result: rejected — password shorter than the 6-character minimum, independent of its character content.
  7. Test case 7 — password too long. Password equivalence class: length > 8.
    login = "carol1", password = "Ab1defghi" (9 chars)
    Expected result: rejected — password longer than the 8-character maximum.
  8. Test case 8 — password missing an upper-case letter. Length is valid (7 chars); character-class equivalence class: no upper-case.
    login = "dave12", password = "ab1defg"
    Expected result: rejected — violates the "must contain an upper-case letter" rule even though the length is valid.
  9. Test case 9 — password missing a lower-case letter. Length is valid (7 chars); character-class equivalence class: no lower-case.
    login = "erin123", password = "AB1DEFG"
    Expected result: rejected — violates the "must contain a lower-case letter" rule.
  10. Test case 10 — password missing a digit. Length is valid (7 chars); character-class equivalence class: no digit.
    login = "frank12", password = "Abcdefg"
    Expected result: rejected — violates the "must contain a number" rule.
Black-box test suite for the authentication subsystem
#LoginPasswordTest intentExpected result
1alice1Abc123Valid baselineAccepted
2bobXyz789Login too short (<6)Rejected
3alice123456Xyz789Login too long (>8)Rejected
4abcdefAb1defgLogin at lower boundary (6)Accepted
5abcdefghAb1defghLogin at upper boundary (8)Accepted
6carol1Ab1dePassword too short (<6)Rejected
7carol1Ab1defghiPassword too long (>8)Rejected
8dave12ab1defgPassword missing upper-caseRejected
9erin123AB1DEFGPassword missing lower-caseRejected
10frank12AbcdefgPassword missing digitRejected