Describe what "Security Awareness Training" is and outline what steps you would include in your security awareness training program.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Describe various ways of measuring a process, with examples.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
You have performed an analysis of production level defects and concluded that many of these defects were introduced inadvertently when changes to other parts of the software were being made. What type of validation technique is used to identify defects caused by modifications to other parts of the code and when is this type of testing appropriate?
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
The IT staff must be aware, understand and embrace quality management principles and practices. List and explain four tactics (e.g., approaches / methods) you would use to communicate these concepts to your IT staff.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Explain why risk prioritization is important and give two methods used to prioritize risk.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
You have been appointed the Information Security Manager of the organization. Senior management wants you to assess and overhaul the security systems and processes. List and describe five information security principles that you will implement as security practices.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
A well-known benefit of process maturity is reduction in cycle time. Explain two ways by which cycle time reduces as process maturity increases.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Control Charts are a statistical technique used to assess, monitor, and maintain the stability of a process. Describe below how you might employ the use of a control chart and describe the main components of a control chart. (NOTE: You do NOT need to draw a chart.)
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
Describe the steps to create a histogram.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
You have been working for years in a company that does not have any defined processes at the organizational level. The organization now wants to adopt CMMI Level 3 practices. You have been promoted to QA Manager and your first order of business is to establish the process definition framework. Describe the steps for effective process definition.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
You have been requested to develop a “customer satisfaction” baseline study. List five factors about the product or the project team that you might include in your customer satisfaction baseline.
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
The eight steps below describe a "Process Improvement Process". Briefly describe what should happen in each step.
Step 1 - Select process and team
Step 2 - Describe current process
Step 3 - Assess process for control and capability
Step 4 - Brainstorm for improvement
Step 5 - Plan how to test proposed improvement
Step 6 - Analyze results
Step 7 - Compare results
Step 8 - Change process or redo steps 4-8
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
In planning for risk response, what are the three categories which can be used for effective planning?
Type your answer in the box provided. Use options on the box toolbar to edit your response as needed before moving to the next question.
It is generally recognized that software testing should begin at which software development phase?
If you found, through testing software, that your IT project team was building software with an average of 58 defects per 1000 function points, this would be a:
When management selects an approach or set of actions to align assessed risks with the organization's risk appetite in the context of strategy and objectives, this is called:
A payroll application requires that each new employee hired have a unique Employee ID and password and that all characters in a field are either numeric or alphabetic. This is an example of a:
Which of the following is / are used for determining the magnitude of the Risk?
If common causes of variation result in a process operating outside the customer's specifications, the process is improved by reducing the special causes of variation.
There are many benefits associated with maturing work processes. As work processes mature, which of the following would be expected to decrease:
What is the risk that an organization faces if management does not take action to alter the risk's likelihood or impact?
For maturing the management process at Level 3, which of the following should be in focus?
Which of the following question(s) is associated with the post-implementation review?
The workbench definition should contain a policy statement. The objective of the policy statement is which of the following?
"Establish Functional Improvement Objectives" is a step in the ____________ of benchmarking.
Causes of variation that are typically "external" to the process are referred to as:
A "task force" is a cross-functional group organized for a specific purpose. Task force management principles include:
Which of the following quality control practices would be considered a validation method?
____________ provides teams an opportunity to reach high-quality decisions with total team commitment.
A "leader" and a "manager" are two terms that basically mean the same thing.
Boundary analysis techniques are used to create test cases that divide equivalence partitioned groups.
When making a judgment while compliance monitoring, experience plays a larger role when:
Out of the three critical aspects of Toyota's JIT concept, which one is the most important?
Process improvement activities should also be conducted as per a defined process.
Which of the following statements completely interprets the 'Act' phase of PDCA cycle?
Laws and regulations affecting the products produced and operated are generally addressed in which planning activity:
Which one of the following best describes "mission statement" for a company or an organization?
A test case tested data values at 0, 9, 10, 11, 49, 50, 51, 100. Which black-box technique was most likely used to generate these data points.
Organizations use many ways to determine the size of a program. Which of the following methods for measuring the size of a program can be used before the coding process is complete?
The team member is told what to do, and then how to check that what was done was done correctly. This statement shows relationship between:
Which of the following activities should occur before processes are defined to ensure that the most critical processes are defined first.
The amount of effort required to intercouple or interconnect computer systems is referred to as:
Which technique is used to develop a common vision of what a process should look like and depicts processes, their relationships, and their owners?
Which of the following would be considered an important prerequisite to quality planning?
Branch testing technique is included in which of the following test data categories?
The stakeholders of security system should be trained on security data collection methods and:
While contracting for outsourced software development, ___________ refers to the rights of the customer to run the application system in more than one location.
Which of the following is NOT a major concerns during the operation and maintenance of a purchased application or software?
Which of the following would be measured subjectively to develop a baseline:
At what process maturity level in the SEI process maturity model would you expect that the most effort would be devoted to quality control?
Checking if the web page on a internet banking site comes up within 2 seconds is an example of:
Which tool is used by teams to help create order out of chaos, by categorizing large numbers of ideas?
If a software development contract includes a clause on foreign attachments, which of the following would be considered a foreign attachment?
A major corporation issued this statement: "We see ourselves now and in the future as a company with a strong customer franchise, known for reliability, trust and integrity in all relationships. Our business will be based on technologies that have evolved over a long history and which will give us unique advantages over our competition. These technologies will span our core businesses and will also go beyond boundaries we can see today." What type of statement is this?
Six Sigma quality is a statistical term defining the number of defects that have been established as a quality objective. A Six Sigma defect rate is:
_______________ is a structured, problem-solving technique used to show the relationship between groupings.
Within an ISO process assessment, a capability level is said to be established 'only' and 'only if' all the process attributes are 'fully achieved'.
Which of the following is not included in 'Failure Cost' under 'Cost of Quality'?
The effort required for testing a program to insure it performs its intended function is called:
The guarantee provided by the contractor of software development that the deliverables will meet the specification is called:
If there is a 50% probability of a risk occurring and the impact of the occurrence is $40,000 lost of revenue, then what is the expected value of the risk?
Which of the following is NOT normally considered one of the questions that must be answered in performing quality planning?
The risk associated with replacing a team member would be characterized as:
Which is the best positioning of a quality manager within the IT organization?
Which of the following is the primary objective of a quality improvement program?
Your manager describes his / her desires and intents concerning a process to you. The manager is describing the:
Which layer of management is the weakest link in a successful quality management program?
-- Exhibit –
-- Exhibit --
In the diagram of the tester's work bench, the box labeled (2) is the:
Many managers use a metrics dashboard to present measurement data to the user of that data. Another name for a dashboard is:
Prior to TQM, the distinction between “little-Q” and “big-Q” was given by: