Bird
0
0

How should a bug be classified if it causes a security vulnerability but affects only a non-critical module with no immediate exploit known?

hard📝 Application Q9 of 15
Testing Fundamentals - Test Documentation
How should a bug be classified if it causes a security vulnerability but affects only a non-critical module with no immediate exploit known?
AMedium severity, low priority
BHigh severity, medium priority
CLow severity, high priority
DHigh severity, high priority
Step-by-Step Solution
Solution:
  1. Step 1: Assess severity of security vulnerability

    Security issues are usually high severity due to potential risk.
  2. Step 2: Assess priority given no immediate exploit and non-critical module

    Priority is medium because no urgent exploit exists and module is less critical.
  3. Final Answer:

    High severity, medium priority -> Option B
  4. Quick Check:

    Security risk = High severity; urgency depends on exploit [OK]
Quick Trick: Security bugs = high severity; priority varies by risk [OK]
Common Mistakes:
  • Ignoring security impact on severity
  • Assuming all security bugs have highest priority
  • Confusing module criticality with severity

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More Testing Fundamentals Quizzes