Fault Attack
A fault attack is a security attack that intentionally introduces faults into a system to expose vulnerabilities or compromise its security mechanisms.
“A test technique to evaluate a specific quality characteristic of a test object by attempting to trigger specific failures.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Fault Attack?
Attackers manipulate hardware or software conditions, such as voltage, timing, or environmental factors, to bypass security controls or extract sensitive information.
Intentional fault creation: Faults are induced deliberately.
Security objective: The goal is to compromise protected systems.
Testing relevance: Security testing evaluates resistance to fault attacks.
Real World Example
An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.
The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Fault attack points testing toward that hostile or risky behavior.
The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.
The team strengthens the controls because Fault attack helps them test the product from the perspective of misuse, not only normal customer journeys.
Practice Questions
Question 1
Which statement BEST describes Fault attack in the context of ISTQB terminology?
Question 2
A tester needs to explain Fault attack to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Fault Attack. Test your understanding with topic-specific questions in our Mock Exams.