"How would you test a login page?" (or an ATM, a payment gateway, a booking system) is one of the most common scenario-based testing interview questions. Interviewers aren't looking for a memorised list; they want to see structure: functional checks, negative and boundary cases, security, usability and failure handling. Each scenario below is organised that way so you can answer any variation.

How to Structure Any "How Would You Test…" Answer

  1. Clarify: ask about requirements, users, platforms and constraints before listing tests.
  2. Functional: the main flows and the rules behind them.
  3. Negative and boundary: invalid input, limits and empty states.
  4. Non-functional: security, performance, usability, accessibility, compatibility.
  5. Failures: what happens when the network, payment or a dependency fails.
  6. Automation: which of these you would automate and at which level (UI or API).
Advertisement

1. How would you test a login page?

AreaWhat to test
FunctionalValid login; invalid username or password; empty fields; case sensitivity of password; Remember me; logout
SecurityAccount lockout after repeated failures; password masked; no credentials in URL; SQL injection and script input handled safely; session expires; back button after logout doesn't restore the session
Usability and othersTab order and Enter key submit; error messages that don't reveal which field was wrong; works on supported browsers and mobile

2. How would you test a signup or registration form?

AreaWhat to test
ValidationRequired fields, email and phone formats, password rules, confirm password match, field length limits, special characters and Unicode names
Business rulesDuplicate email or username rejected; age or country restrictions; terms checkbox required
After submitAccount created in the database, verification email sent, user can log in, data stored exactly as entered

3. How would you test a forgot-password feature?

AreaWhat to test
RequestRegistered and unregistered emails (same neutral message, so attackers can't discover accounts); invalid formats; rate limiting on repeated requests
Reset linkArrives by email; works once; expires after the set time; old links stop working after a new request or a successful reset
New passwordPassword rules enforced; can't reuse old password if that's a rule; old password no longer works; other sessions logged out

4. How would you test add to cart?

AreaWhat to test
CoreAdd one and several items; quantity changes; same item twice; remove items; cart count and totals update
RulesOut-of-stock and maximum quantity; price and discount applied correctly; variants such as size and colour kept
PersistenceCart kept after refresh, across tabs, after login (guest cart merges) and after logout as designed

5. How would you test a payment gateway?

AreaWhat to test
Happy pathSuccessful payment with each supported method (cards, UPI, wallets, net banking) using sandbox data
FailuresDeclined card, insufficient funds, wrong OTP, timeout, user closes the payment page; order state stays correct and no double charge
IntegrityAmount, currency and rounding; refresh or back button during payment; duplicate clicks; refunds; confirmation email and database records
SecurityHTTPS, card data never stored or logged, 3-D Secure flows
AreaWhat to test
ResultsExact, partial and case-insensitive matches; no results message; relevant ordering
InputEmpty search, very long text, special characters, Unicode, leading and trailing spaces, injection-like input
FeaturesFilters, sorting, pagination, suggestions/auto-complete, search history
PerformanceResponse time on large data sets

7. How would you test file upload and download?

AreaWhat to test
UploadAllowed types and sizes; size limit exceeded; zero-byte and very large files; multiple files; file names with spaces or Unicode; cancel mid-upload
SecurityDisallowed types renamed with an allowed extension; malicious content; path-traversal names
DownloadCorrect file, name and content; large files; unauthorised users blocked

8. How would you test an email field?

AreaWhat to test
Valid formatsPlus addressing, subdomains, long but valid addresses, upper case
Invalid formatsMissing @ or domain, spaces, double dots, trailing dot, very long input
BehaviourTrimming spaces, uniqueness check, error message wording, copy-paste

9. How would you test dropdowns and radio buttons?

AreaWhat to test
DropdownDefault value, all options present and spelled correctly, order, selection saved, dependent dropdowns refresh, keyboard selection
Radio buttonsOnly one selectable per group, default selection, label click selects, required validation

10. How would you test an ATM?

AreaWhat to test
Card and PINValid and invalid card, expired or blocked card, wrong PIN, card retained after three wrong PINs
TransactionsWithdrawal within balance and daily limit, denominations, insufficient funds, balance enquiry, mini statement, deposit
FailuresPower loss or network failure mid-transaction (account not debited without cash), cash jam, receipt printer out of paper, timeout returns card
Usability and securityScreen readability, language options, card and cash not left in the slot, shoulder-surfing protection

11. How would you test a calculator app?

AreaWhat to test
OperationsAddition, subtraction, multiplication and division with positive, negative and decimal numbers; order of operations
Edge casesDivision by zero, very large numbers, many decimals, repeated equals, clear and backspace
UIKeyboard input, display overflow, copy and paste

12. How would you test a mobile app login screen?

AreaWhat to test
FunctionalEverything from the web login plus biometric login and OTP login
Mobile-specificKeyboard types for email and password, screen rotation, app backgrounded mid-login, poor or no network, push-notification interruption
DevicesDifferent screen sizes and OS versions, permission prompts

13. How would you test a booking system (bus, flight, hotel)?

AreaWhat to test
SearchDates, past dates rejected, return before departure rejected, passenger counts, no availability
BookingSeat selection, price breakdown, simultaneous booking of the last seat (only one succeeds), payment and confirmation, ticket and email
ChangesCancellation and refund rules, rescheduling, time zones on flights

14. How would you test an online exam portal?

AreaWhat to test
Before the examLogin, exam available only in its time window, instructions
DuringTimer accuracy and auto-submit at time-out, answers saved on refresh or network drop, navigation between questions, no copy or tab switching if that's a rule
AfterScore calculation, result publishing, attempt limits, reports for the examiner

15. How would you test an e-commerce checkout end to end?

AreaWhat to test
FlowCart → address → delivery → payment → confirmation, as guest and logged-in user
CalculationsTaxes, shipping, coupons and their combinations, rounding
IntegrityInventory reduced once, order and payment records match, emails sent, order visible in history
FailuresPayment failure, address validation errors, session timeout mid-checkout

For defect and project situations, continue with defect-handling scenario questions and requirement and release scenario questions.

FAQs

How do I answer "how would you test a pen" type questions?

Ask clarifying questions first, then cover functional, negative and boundary, non-functional (usability, durability, safety) and failure scenarios, and say which you would prioritise. The structure matters more than the length of the list.

Should I mention automation in scenario answers?

Yes, briefly: say which checks you would automate (stable, repetitive, data-driven ones) and at which level, for example validating payment rules through the API rather than the UI.