NivaarExam PrepOfficial exam papers ↗

19-Soft-A6 Software Quality Assurance · Undated paper

Question 7 of 8

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

04-Soft-A6, Software Quality Assurance — National Exams, May 2019 (3 hours, open book, 8 questions of equal value; FIVE constitute a complete exam paper, and the first five as they appear in the answer book are marked — all eight are solved here as a study resource).

Reference texts: Pressman, Software Engineering: A Practitioner's Approach, 9th ed. (SQA planning, review, testing strategies/techniques, software metrics, reliability & safety); Sommerville, Software Engineering, 10th ed. (software process, configuration management, project monitoring); ISO/IEC 25010 SQuaRE and its predecessor ISO/IEC 9126 (software quality characteristics); ISO/IEC 12207 (life-cycle/configuration-management processes).

Question 7 (10 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

These three activities are the phases of a formal SQA audit — the SQA activity most directly "visible to management," since an audit produces a documented deliverable and finding that management reviews and acts on, unlike the many day-to-day inspection/review activities embedded inside the engineering work itself.

Part (a) — Audit Planning. Before an audit takes place, the audit team defines its scope (which work products, processes, or project phase are being audited), the standards/criteria the audit will check compliance against (the project's SQA plan, coding standards, applicable ISO/IEC 12207 or contractual requirements), the audit schedule and required participants, and the checklist or audit criteria that will structure the audit meeting. Planning also identifies which artifacts the auditee must have ready (baselined documents, review records, defect logs) so the audit itself is not spent locating evidence. Good planning is what makes the audit's findings defensible and repeatable rather than an ad hoc, subjective walkthrough.

Part (b) — Audit Meeting. The audit meeting is where the planned checks are actually carried out: the audit team examines the identified artifacts and process evidence against the criteria set in planning, interviews the responsible engineers where needed, and records every non-conformance found (a missed review, an un-updated baseline, a process step skipped) along with its severity. The meeting is conducted objectively and non-confrontationally — its purpose is to establish facts about conformance, not to assign blame to individuals — and every finding raised must be traceable to a specific criterion from the audit plan, not a reviewer's personal opinion.

Part (c) — Audit Reporting. The audit's findings are consolidated into a formal audit report: each non-conformance is documented with its severity, the criterion it violates, and (where applicable) a required corrective action and due date. The report is distributed to project management and the responsible engineering leads, who own tracking each corrective action to closure. This is the step that makes the audit "visible to management" in the fullest sense — a documented report, with named owners and dates, gives management the concrete decision point (accept the risk, fund the fix, escalate) that an informal verbal finding never would.