Monash University · FACULTY OF INFORMATION TECHNOLOGY

FIT2001 Chap.10 Security, Testing and Quality Evidence

- one subject, every graph, every model, every mark
5 Chapters3-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 10 of 11 · FIT2001

Security, Testing and Quality Evidence

Define threat scenario

The course material gives this chapter a concrete anchor: Week 10 places security and testing inside systems design rather than after implementation.

That threat scenario anchor controls how test oracle is explained and how traceability matrix is tested in changed practice.

Security, Testing and Quality Evidence turns threat scenario, test oracle and traceability matrix into executable reasoning.

The chapter's practical target is to connect security and quality risks to requirements, tests and evidence, so every explanation should connect syntax to program state, control flow and observable output.

Treat threat scenario as a precise program object, not a loose label. Identify the value or responsibility of threat scenario before execution, then trace what can read it, change it or depend on it.

This makes state changes visible before they become debugging guesses.

Use test oracle to explain the program's next move. Work through one representative test oracle input by hand and name the branch, iteration or call that follows.

If the test oracle trace cannot be stated, the code may run by accident rather than by understood design.

Trace test oracle

Bring in traceability matrix as the test of structure.

Compare normal, boundary and invalid inputs for traceability matrix; state the expected behaviour first; then use the mismatch between expectation and result to localise the defect.

For the application — connect security and quality risks to requirements, tests and evidence — write the smallest complete example that exposes the rule.

Explain why the traceability matrix result works, what would break it and how the program should signal or recover from that failure.

Before running an example involving threat scenario, make a trace table with the important state before and after each operation. Include the value associated with threat scenario, the control decision governed by test oracle and the output or object affected by traceability matrix.

The threat scenario table turns an unexplained result into a sequence that can be tested one transition at a time.

Test three inputs: an ordinary case, a boundary case and an invalid case. State the expected traceability matrix result for each before execution, then compare it with what the program actually does.

A useful test of test oracle isolates one rule; changing several conditions at once cannot reveal which condition caused the failure.

Test with traceability matrix

Practise explaining the solution without reading the code.

For fit2001, name the data representation, the control flow, the responsibility of each function or class and the reason the chosen design supports connect security and quality risks to requirements, tests and evidence.

This traceability matrix rehearsal matters when a written test or interview asks why the program works rather than whether it produces one correct output.

A complete response should make the task visible before the detail: identify what must be decided, define the relevant terms, connect the evidence to test oracle, and use traceability matrix to test the result.

The final sentence about traceability matrix should answer the question actually asked rather than merely repeat the topic.

The controlling limit is specific: Test count and code coverage do not prove important behaviour or threat resistance.

Keep that traceability matrix limit beside the worked example, because it separates a careful fit2001 answer from one that sounds confident but claims more than the task or evidence supports.

For revision, retrieve threat scenario, test oracle and traceability matrix without notes, explain their relationship aloud, then complete a changed version of the application: connect security and quality risks to requirements, tests and evidence.

Record the first failed test oracle reasoning move and repair it before attempting another case.

In this chapter

What this chapter covers

  • 01

    threat scenario

  • 02

    test oracle

  • 03

    traceability matrix

  • 04

    Applying threat scenario

  • 05

    Limits of test oracle and traceability matrix

Worked example · free

Test an account reset

Q [4 marks]. AskSia-authored practice. A reset flow passes normal tests but leaks whether an email is registered. Build a better test set.
  • 1State confidentiality and abuse requirements.
  • 1Create registered and unregistered cases with the same public response.
  • 1Test rate, token expiry and replay.
  • 1Trace every result to evidence and residual risk.
The public response and timing should not disclose account existence, while valid tokens are single-use, expiring and rate-controlled; tests must cover misuse as well as success.
Sia tip — A security requirement needs an adversarial oracle.
Glossary

Key terms

threat scenario
Actor, capability and action that could violate a protected system property. This chapter uses the concept when students connect security and quality risks to requirements, tests and evidence. Use this definition when the task is to connect security and quality risks to requirements, tests and evidence.
test oracle
Rule or expected outcome used to decide whether observed behaviour is correct. It helps explain the reasoning required to connect security and quality risks to requirements, tests and evidence. Use this definition when the task is to connect security and quality risks to requirements, tests and evidence.
traceability matrix
Mapping among requirements, design elements and verification evidence. Its limit matters because test count and code coverage do not prove important behaviour or threat resistance. Use this definition when the task is to connect security and quality risks to requirements, tests and evidence.
FAQ

Security, Testing and Quality Evidence FAQ

What is the main task in Security, Testing and Quality Evidence?

Connect security and quality risks to requirements, tests and evidence.

How do threat scenario and test oracle work together?

Use threat scenario to establish the object or condition, then use test oracle to explain how it changes the outcome being analysed.

What must a fit2001 answer qualify here?

Test count and code coverage do not prove important behaviour or threat resistance.

How should I revise Security, Testing and Quality Evidence?

Retrieve threat scenario, test oracle and traceability matrix, apply them to a changed case, and correct the first point where the evidence no longer supports the conclusion.

Study strategy

Exam move

Reconstruct the relationship among threat scenario, test oracle and traceability matrix; complete the chapter application without notes; then test the result against this limit: Test count and code coverage do not prove important behaviour or threat resistance.

Working through Security, Testing and Quality Evidence in FIT2001? Sia is AskSia’s AI Information Technology tutor — ask any FIT2001 Security, Testing and Quality Evidence question and get a clear, step-by-step explanation grounded in how FIT2001 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 69 of your Monash University subjects - and 1,000+ Bibles across every Australian university.
Sia - your FIT2001 tutor, unlimited, worked the way the exam marks it
The full 3-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works
Unlock the full FIT2001 Bible + 69 Monash University subjects
$0.99 Trial