Test Strategy for Example 2 maybe should contain checking that we don't change any other user's entity field but only password. But this could mess up the test. What do you think? What is your assessing path to decide whether include or not anything to test?