Software testing techniques help you turn requirements, code paths, and known risks into a small, defensible set of test cases. There is no single technique that finds every kind of defect: choose based on what you know about the system, what could go wrong, and what you need to cover. This guide explains the main black-box, white-box, and experience-based techniques, then shows how to combine them around a sample account-lockout requirement.
What are software testing techniques?
A testing technique is a systematic way to analyze a test basis and design tests from it. The test basis might be a requirement, acceptance criterion, business rule, interface, code structure, or the tester’s knowledge of common failures. Techniques help avoid choosing cases arbitrarily: instead of trying every possible input, you select cases that represent meaningful behavior, limits, combinations, or paths.
The ISTQB Certified Tester Foundation Level (CTFL) Syllabus v4.0, dated April 21, 2023, groups techniques into three families: black-box, white-box, and experience-based. The syllabus says experience-based techniques can detect defects that black-box and white-box techniques may miss. The families complement one another; none proves that software is defect-free or that it meets every user need.
How do I choose a testing technique?
Start with the question you need the tests to answer, then match the technique to the test basis and risk. A stable requirement may support black-box cases; source code or a control-flow diagram enables white-box coverage; domain knowledge and defect history can guide experience-based probes. For a single feature, combining methods is often more useful than trying to make one method do everything.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
- Identify the test basis: Is the best available evidence a specification, internal design or code, or tester knowledge?
- Name the risk: Are you concerned about invalid input, a misplaced limit, interacting rules, an invalid event sequence, an unexecuted code path, or an unexpected behavior?
- Choose a coverage item: Decide whether you will count partitions, boundaries, rule combinations, transitions, statements, or branches. State what the count means; “100% coverage” is incomplete without saying what was covered.
- Check what you need: Some methods need clear, stable requirements; white-box testing needs suitable implementation access; useful experience-based testing depends on relevant skill and context.
- Balance value and upkeep: Consider how much effort it takes to design, execute, and maintain the cases in your environment. There is no universal cost or effectiveness ranking.
Black-box techniques: test specified behavior
Black-box test cases come from specified behavior rather than implementation details. Their test basis can include requirements, rules, interfaces, or acceptance criteria. If the implementation changes but required behavior does not, these tests can remain useful. CTFL v4.0 covers equivalence partitioning, boundary-value analysis, decision-table testing, and state-transition testing as black-box techniques.
Equivalence partitioning: test representative input groups
Equivalence partitioning divides inputs into sets that are expected to receive the same treatment. A tester samples at least one representative from every relevant partition rather than checking every value. Include valid and invalid partitions where the requirements define different outcomes. Partitions should be non-empty and non-overlapping; complicated behavior may require more careful partitioning than a quick list of “good” and “bad” data.
Example: Suppose an illustrative login requirement says an account identifier must be a registered email address. Possible partitions are a registered address (accepted for password checking), an unregistered but syntactically valid address (rejected), a malformed address (validation error), and a missing address (required-field error). Those groups are only appropriate if the requirement really distinguishes their behavior; do not create partitions for imagined outcomes.
Boundary-value analysis: focus on ordered limits
Boundary-value analysis applies to ordered partitions, where errors often occur at the edge: a limit may be shifted, omitted, or handled with the wrong inclusive or exclusive comparison. First state the rule’s endpoints and whether each endpoint is allowed. Then select the adjacent values required by the chosen method. A two-value method and a three-value method use different sets of values, so name which convention your test plan uses.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Example: For a fictional rule that locks an account after five consecutive failed attempts, test the point just below the threshold, the threshold itself, and just above it: four, five, and six failures. Check the specified result at each point. This example assumes the threshold is five and that the rule says “after five”; it is not a general account-security recommendation. Also test a reset or successful-login boundary if the requirement specifies how attempts are cleared.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Decision-table testing: cover rule combinations
Use a decision table when combinations of conditions determine an action, especially for business rules. List the meaningful conditions, the combinations that can occur, and the expected action for each rule. Select tests to cover those rules. Tables make omissions and conflicting outcomes easier to see than a paragraph of prose.
For a fictional checkout rule, “place order” might depend on whether the account is active, payment is valid, and the item is in stock:
| Account active | Payment valid | Item in stock | Expected action |
|---|---|---|---|
| Yes | Yes | Yes | Accept the order |
| No | Yes | Yes | Reject; require an active account |
| Yes | No | Yes | Reject; report payment failure |
| Yes | Yes | No | Reject; report unavailable stock |
This compact table illustrates individual failure conditions. If the actual requirements define different combinations, such as whether an unavailable item should be reported alongside a payment failure, add those combinations and expected actions rather than assuming this table is complete.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11State-transition testing: test events and sequences
State-transition testing models how events move a system between states. A model can include states, events, optional guard conditions, and actions. Derive cases that exercise valid transitions and, where relevant, invalid transitions or sequences. State diagrams or transition tables help expose missing paths. Testing only individual screens or isolated events can miss failures that depend on order.
For the fictional lockout rule, a simple sequence might be: active account → failed login (one failure) → failed login (count advances) → fifth consecutive failure (locked) → password reset or administrator recovery (active again). Test the required outcome at each event, including whether another login is allowed while locked and which recovery events are valid. Those details must come from the product’s rules.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
White-box techniques: test internal structure
White-box test design uses internal control flow or code structure. CTFL v4.0 highlights statement testing and branch testing. Statement coverage asks whether each executable statement was run; branch coverage asks whether each branch, or transfer of control between nodes in a control-flow graph, was exercised. A branch may be conditional or unconditional.
Consider this illustrative code:
if (failedAttempts >= 5) {
lockAccount();
}
showLoginResult();
Running the code with four failures executes showLoginResult() but not lockAccount(). Running it with five failures executes both. Those two tests execute every statement, but statement coverage alone does not show that both outcomes of the condition were exercised. Testing four and five exercises the false and true outcomes of that condition. This example demonstrates the distinction; real control flow may have more branches, conditions, or paths.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →White-box coverage can reveal implementation paths that requirements-only testing misses, and it is useful when a specification is vague, outdated, or incomplete. It cannot establish by itself that the implementation matches user needs: code can be thoroughly exercised and still implement the wrong behavior.
Experience-based techniques: use tester knowledge deliberately
Experience-based techniques draw on the tester’s domain knowledge, previous defects, and understanding of how users or systems behave. They are skill-dependent and complement systematic black-box and white-box methods.
Error guessing
Use defect history and domain knowledge to propose focused probes. For a login workflow, a tester might investigate repeated submissions, unusual input lengths, recovery after lockout, or whether an account’s state behaves consistently across sign-in and reset flows. Treat each idea as a hypothesis to check against the product’s behavior and risks—not as proof that the behavior is defective.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Exploratory testing
Exploratory testing combines learning, test design, execution, and evaluation as the tester works; what the tester learns guides the next action. Give a session a clear charter and timebox so it remains focused. For example:
- Charter: Explore how a user recovers access after repeated login failures.
- Timebox: Set a session length appropriate to the feature and team.
- Observe: Record actions, outcomes, unexpected states, and useful questions about the rules.
- Follow up: Turn relevant observations into reproducible cases, requirements questions, or defect reports.
Checklist-based testing
A checklist turns known risk prompts into repeatable reminders. For a login flow, a team might check missing and malformed fields, attempt thresholds, lockout behavior, and recovery events. Keep prompts specific enough to guide inspection but not so prescriptive that they replace judgment or hide newly discovered risks.
Collaborate before implementation to make behavior testable
When requirements are still being created, collaborative user-story writing, explicit acceptance criteria, and acceptance test-driven development can make expected behavior clearer before implementation. This is upstream of test design: conditions and examples agreed by the people involved give later black-box testing a better basis. A useful criterion describes an observable outcome and relevant conditions, rather than only the feature’s intention. CTFL v4.0 covers collaboration-based approaches alongside core testing techniques.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Where do techniques fit in the test lifecycle?
Test levels and test types describe different things. CTFL v4.0 names five levels: component, component-integration, system, system-integration, and acceptance. Levels group testing activities by the scope of software under test. The syllabus also addresses functional and non-functional testing, as well as black-box and white-box approaches, as test types. Most types can be performed at different levels; for example, functional testing is not limited to system testing.
After an enhancement or defect fix, distinguish two purposes:
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
- Confirmation testing: Check whether the particular fix or change works as intended.
- Regression testing: Check whether the change adversely affected other areas.
As practical guidance, choose regression scope according to risk and affected dependencies; there is no one-size-fits-all scope. A change’s likely impact and connections to other parts of the system should inform what to retest.
How can screenshots support testing?
A screenshot can preserve visual evidence of a page state for review or comparison, but capturing an image is not a substitute for the techniques above. Define what you want to inspect—such as whether the expected page rendered after a workflow step—and keep the tested URL and relevant conditions consistent. For automated checks, decide how you will handle dynamic content and what counts as a meaningful visual difference; a screenshot alone does not establish that the underlying behavior is correct.
One do-it-yourself option is to open the target page in a browser, reach the state you want to inspect, and use the browser’s screenshot facility to save the page or visible area. Repeat the same steps for the comparison state and review the images against the expected result. This is simple for occasional checks, but the browser setup and repeatable capture conditions are your responsibility.
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server for developers. Its one-call API accepts a URL and returns a PNG, JPEG, WebP, or PDF; options include full-page capture, CSS selectors, custom CSS and JavaScript, waits, and device viewports. It accepts cookie or consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status in headers.
Free tools Windows power users keep installed
One-click scans. No signup required.
cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo API documentation for setup and request options. The MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, or another MCP client. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. See ScreenshotNeo for plan details. Sign up for 1,000 free screenshots a month—no card required.
Common mistakes to avoid
- Sampling only valid inputs: Include relevant invalid and missing partitions when the specified behavior distinguishes them.
- Checking a limit without defining it: Write down whether endpoints are inclusive, then test the adjacent values required by the selected boundary method.
- Testing business rules one condition at a time: Use a decision table when combinations change the expected action.
- Testing states without sequences: Exercise transitions in event order, including meaningful recovery and invalid transitions.
- Equating code coverage with correctness: State and branch coverage describe exercised implementation structure, not whether the behavior meets user needs.
- Relying only on intuition: Experience-based probes add value alongside, not instead of, systematic methods.
- Using “coverage” without naming its unit: Say what has been covered—partitions, boundaries, rules, transitions, statements, or branches.
Frequently asked questions
Do testing techniques guarantee that a product has no defects?
No. Techniques help select and organize tests, but the results only provide evidence about the cases and coverage items exercised.
Is exploratory testing the same as testing without a plan?
No. Exploratory work can be guided by a charter and timebox; the tester adapts test design as new information emerges.
Can a team use more than one technique for the same feature?
Yes. Different techniques target different risks, so a feature may warrant a combination—for example, requirement-based partitions, boundary checks, and code-branch tests.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

