ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium

A software company is preparing to release a new version of its popular accounting software. Before release, the product manager mandates a final review to ensure that all features and functions perform as intended, without any unexpected side effects, and that the software meets its specified security requirements. Which type of testing is this primarily focused on?

  1. AUnit Testing
  2. BFuzz Testing
  3. CRegression Testing
  4. DAcceptance Testing
Show answer & explanation

Correct answer: D. Acceptance Testing

The scenario describes testing to ensure the software performs as intended, meets specified requirements (including security), and is ready for release. This aligns with the purpose of Acceptance Testing, which verifies that the system meets the business requirements and is acceptable for delivery.

Why the other options are wrong

  • A. Unit testing tests individual components or modules of the software.
  • B. Fuzz testing involves providing invalid, unexpected, or random data inputs to a computer program.
  • C. Regression testing ensures new changes haven't broken existing functionality.

Acceptance Testing

A formal testing process conducted to determine if the requirements of a specification or contract are met, and to verify if the system is acceptable for deployment.

  • Performed by end-users or product owners.
  • Often the final stage of testing before release.
  • Ensures the software fulfills business needs and expectations.

Memory trick: Units built, integrated, system checked, then accepted by users.

More Security and Risk Management questions