ISTQB CT-GenAI Practice Test Questions and Exam Dumps Part17 Q321-340

View Full ISTQB CT-GenAI Exam Dumps and Practice Test Dumps.

 

Question 321

A tester asks GenAI to generate test cases for a feature using an outdated requirements document. What is the primary risk?

  1. The generated tests may reflect obsolete behavior
  2. The model will automatically identify the latest requirements
  3. The tests will always contain fewer steps
  4. The model will refuse to generate the tests

Correct Answer: 1

Explanation

Using outdated requirements can cause GenAI to generate tests based on behavior that is no longer valid. The resulting cases may contain obsolete business rules, incorrect expected results, missing new functionality, or unsupported assumptions. Testers should therefore confirm that the source material is current and approved before using it for generation. Version information can also be included in the prompt to clarify which specification applies. GenAI does not automatically know project-specific changes unless those changes are provided through reliable context. Generated tests should subsequently be compared with the current requirements before being accepted into the test suite.

Question 322

A tester wants GenAI to generate tests for both authorized and unauthorized users of an application. Which information should be included in the prompt?

  1. Only the application’s name
  2. User roles, permissions, and expected access behavior
  3. The preferred font for test reports
  4. The number of testers on the project

Correct Answer: 2

Explanation

Authorization testing depends on understanding which users can perform particular actions and which actions should be denied. Providing user roles, permissions, and expected access behavior gives GenAI the necessary context to generate relevant positive and negative authorization scenarios. Without this information, the model may assume incorrect permissions or overlook important combinations. The generated tests should still be checked against the approved access-control specification because model-generated assumptions are not authoritative. Clear role and permission information can improve coverage of allowed and prohibited operations, helping testers identify potential authorization gaps while retaining human responsibility for validating the generated scenarios.

Question 323

A GenAI tool generates test cases that include an unsupported API endpoint. What should the tester do?

  1. Add the endpoint to the application
  2. Execute the test immediately
  3. Verify the endpoint against current authoritative API documentation
  4. Assume the endpoint is part of a future release

Correct Answer: 3

Explanation

An unsupported API endpoint may be a hallucinated or outdated detail. The tester should verify the endpoint against current API specifications, provider documentation, or another authoritative source before using it. Executing a test against a nonexistent endpoint can waste time and produce misleading results. The tester should not modify the application or assume that the endpoint belongs to a future release without evidence. This illustrates the importance of factual validation for generated technical information. GenAI can suggest useful API scenarios, but authoritative documentation should determine which endpoints, parameters, methods, and expected responses are actually supported.

Question 324

Which practice best helps maintain consistency when multiple testers use GenAI to generate test cases for the same project?

  1. Allow every tester to use completely different terminology
  2. Avoid defining any output format
  3. Use agreed prompts, terminology, examples, and output structures
  4. Let each tester invent requirements independently

Correct Answer: 3

Explanation

Shared prompting guidance can improve consistency when multiple testers use GenAI for similar activities. Standard terminology, representative examples, required fields, and agreed output structures help reduce unnecessary differences between generated artifacts. This does not mean that every response will be identical because generative systems can produce variations. Testers should still review the resulting cases for correctness and project-specific applicability. Independent terminology and invented requirements can create confusion and reduce traceability. A common prompting approach can therefore support collaboration, review, and maintainability while preserving appropriate human judgment over the final test artifacts.

Question 325

A tester asks GenAI to create tests for a field that accepts dates only from January 1 through December 31. Which testing approach should be considered?

  1. Test only dates in the middle of the year
  2. Include boundary and invalid-date conditions
  3. Test only the current date
  4. Avoid testing dates outside the valid range

Correct Answer: 2

Explanation

Boundary and invalid-value testing can reveal defects in date validation. For a defined valid range, testers should consider the start and end boundaries, values immediately around those boundaries where applicable, and invalid dates that should be rejected. Testing only typical dates may miss defects in validation logic. GenAI can help generate combinations such as minimum and maximum dates, invalid formats, impossible dates, and out-of-range values. However, the tester should verify these scenarios against the actual requirement because the precise interpretation of the date range may depend on business rules, time zones, or other constraints.

Question 326

A tester uses GenAI to generate test scripts and notices that the generated code handles errors differently from the existing automation framework. What should be checked?

  1. Whether the generated error handling conforms to the project’s approved framework and standards
  2. Whether the generated code is longer
  3. Whether the model used technical language
  4. Whether the script contains more comments

Correct Answer: 1

Explanation

Generated automation should conform to the project’s established framework, coding standards, error-handling conventions, and maintainability requirements. If the generated code handles failures differently, the tester should determine whether that behavior is appropriate and consistent with existing automation. Inconsistent error handling can make failures harder to diagnose and may cause important errors to be hidden. Code length or comment quantity does not establish quality. The tester should review the generated implementation and compare it with approved project practices before accepting it. GenAI can accelerate coding, but generated code remains subject to the same engineering standards as manually written automation.

Question 327

A tester wants GenAI to suggest tests for a requirement containing the phrase “the response should be fast.” What should the tester consider first?

  1. Ask GenAI to define “fast” independently
  2. Replace the requirement with a longer sentence
  3. Clarify the measurable performance expectation with the appropriate stakeholder
  4. Ignore the performance requirement

Correct Answer: 3

Explanation

The term “fast” is ambiguous because it does not specify a measurable response-time target or applicable conditions. Before generating reliable performance tests, the tester should seek clarification from the appropriate requirements or product stakeholder. The requirement might need a specific threshold, measurement method, workload, or percentile. GenAI can identify ambiguous language and suggest questions, but it should not establish the official business expectation. Once a measurable requirement is available, GenAI can help generate suitable performance scenarios. This improves testability and reduces the risk of generating tests based on arbitrary assumptions about what “fast” means.

Question 328

A tester wants to use a GenAI-generated test summary in a formal project report. What should happen before publication?

  1. The summary should be checked against authoritative execution results
  2. The model should approve its own summary
  3. All numerical results should be removed
  4. The tester should publish it without review

Correct Answer: 1

Explanation

Formal test summaries should be based on accurate and verified execution information. The tester should compare generated statistics, pass and fail counts, defect references, scope information, and significant findings against authoritative test-management or execution records. GenAI can help organize and communicate the information, but it should not be considered the source of truth. Publishing unchecked content could introduce incorrect metrics or misleading conclusions into formal reporting. Human review provides an important quality control step. The level of review should reflect the importance and risk of the report, with greater scrutiny applied to information used for significant project decisions.

Question 329

A tester notices that GenAI-generated test cases repeatedly favor common user workflows and omit rare but high-risk scenarios. What should the tester do?

  1. Remove all common workflows
  2. Add relevant high-risk scenarios and provide appropriate risk context to GenAI
  3. Accept the generated suite because common workflows are sufficient
  4. Generate more copies of the common workflows

Correct Answer: 2

Explanation

Common workflows are useful but may not provide adequate coverage of rare or high-risk conditions. The tester should identify the relevant risks and ensure that those scenarios are represented in the test objectives and prompt context. GenAI can then be asked to generate targeted cases for the identified risks. The existing common workflows do not necessarily need to be removed; instead, the suite should be balanced according to requirements and risk. Simply generating more common cases will not address the missing high-risk conditions. Human risk analysis remains important because GenAI may naturally emphasize frequently described or obvious scenarios.

Question 330

Which statement best describes synthetic test data generated by GenAI?

  1. It is automatically identical to real production data
  2. It never requires validation
  3. It can provide controlled data variations but should be checked for suitability and privacy
  4. It eliminates all data-management responsibilities

Correct Answer: 3

Explanation

GenAI can generate synthetic data representing different customer types, input combinations, boundary conditions, or other testing scenarios. Such data can reduce reliance on sensitive production records, but it is not automatically accurate or suitable. Testers should validate the generated values against business rules, required distributions, formats, relationships, and privacy requirements. Synthetic data may also contain unrealistic patterns or accidentally reproduce sensitive information if the generation process is not controlled. Therefore, synthetic data is a useful testing resource rather than an automatic substitute for validation. Organizations should continue applying their data-handling and security policies when creating and storing generated test data.

Question 331

A tester asks GenAI to produce test cases in JSON format, but the generated response contains invalid JSON. What should the tester do?

  1. Treat the response as valid because the content is understandable
  2. Validate and correct the structure before using it in an automated process
  3. Import it directly into the test-management system
  4. Remove all structured fields

Correct Answer: 2

Explanation

Structured output must be syntactically valid before it can safely be consumed by an automated process. The tester should validate the JSON structure and correct formatting problems or refine the prompt to reduce recurrence. Even valid JSON does not guarantee that the contained testing information is accurate, so both structure and content require review. Importing malformed data directly can cause processing errors or corrupt test-management information. Explicit schemas, examples, and validation checks can improve structured generation. GenAI can assist with producing machine-readable output, but automated workflows should include appropriate validation rather than trusting generated formatting without verification.

Question 332

A tester is reviewing GenAI-generated security test cases. Which factor is most important when determining whether a scenario should be retained?

  1. Whether the scenario is relevant to an identified security requirement or risk
  2. Whether the scenario has the longest description
  3. Whether the model generated it first
  4. Whether it contains unusual technical words

Correct Answer: 1

Explanation

Security test scenarios should have a clear relationship to relevant security requirements, threats, controls, or identified risks. This helps ensure that testing effort is directed toward meaningful security concerns rather than arbitrary model-generated ideas. Length, generation order, and technical terminology do not establish relevance. GenAI can generate useful possibilities such as unauthorized access, privilege escalation, insecure input handling, or session weaknesses, but each scenario should be assessed against the actual system and security context. Qualified testers should also verify that the expected behavior and test conditions are appropriate before execution.

Question 333

A GenAI-generated test references a product feature that was removed in the latest release. What does this demonstrate?

  1. The need to validate generated content against current product information
  2. That all generated tests should be accepted
  3. That historical information is always more reliable
  4. That requirements no longer matter

Correct Answer: 1

Explanation

Generated content can reflect information that is outdated relative to the current version of a product. A removed feature may still appear in generated scenarios if the model has encountered older information or if outdated source material was supplied. Testers should therefore verify generated cases against the current approved requirements, release information, and product documentation. Maintaining version-specific context can reduce this risk. Historical information can remain useful for regression analysis, but it should not be confused with current product behavior. This example reinforces the importance of validating GenAI output against authoritative and current project information.

Question 334

A tester asks GenAI to review a requirement and identify potential test conditions. Which output should be treated as most reliable?

  1. A generated assumption about undocumented functionality
  2. A test condition directly supported by the supplied approved requirement
  3. A feature suggested by the model
  4. A behavior copied from an unrelated application

Correct Answer: 2

Explanation

A test condition directly supported by an approved requirement has a stronger factual basis than generated assumptions or information borrowed from unrelated systems. GenAI can identify potential interpretations and suggest additional scenarios, but the requirement remains the authoritative source for intended behavior. Unsupported functionality should be verified before being used in testing. This distinction helps prevent hallucinations and irrelevant scenarios from entering the test suite. Testers can use GenAI to expand analysis while maintaining traceability to approved sources. Generated suggestions that lack direct support may still be useful as questions for stakeholders, but they should not automatically become test expectations.

Question 335

A team wants to reduce the risk of confidential information being included in prompts. Which control is most appropriate?

  1. Establish clear rules about permitted data and use approved GenAI services
  2. Encourage testers to paste complete production databases
  3. Disable all security review
  4. Allow any external GenAI tool to process project information

Correct Answer: 1

Explanation

Clear data-handling rules help testers understand what information can and cannot be entered into GenAI systems. Approved services can provide appropriate security and contractual controls, while data classification can help determine whether information requires anonymization, redaction, or another protection mechanism. Allowing unrestricted external processing increases the risk of confidentiality breaches. Complete production databases should not be shared merely for convenience. Organizations should also provide practical guidance so testers can use GenAI productively without accidentally exposing sensitive material. Governance, approved tooling, and appropriate data-handling procedures together create stronger controls around GenAI-assisted testing activities.

Question 336

A tester asks GenAI to generate tests for a requirement with multiple business-rule combinations. Which approach can help increase scenario coverage?

  1. Ask for representative combinations of the relevant business conditions
  2. Request only the most common combination
  3. Tell the model to ignore exceptional conditions
  4. Remove the business rules from the prompt

Correct Answer: 1

Explanation

Complex business rules often create multiple combinations that may require separate testing. Asking GenAI to consider representative combinations of relevant conditions can help identify scenarios that might otherwise be overlooked. The tester should specify the applicable rules, constraints, and expected outcomes so that the generated combinations are grounded in the actual specification. Focusing only on common conditions can miss important exceptions and interactions. Removing business rules would further reduce the quality of generated scenarios. The resulting combinations should be reviewed using appropriate test-design techniques and risk information to determine whether they provide meaningful coverage.

Question 337

A tester discovers that GenAI generated several test cases with identical objectives but different wording. What is the appropriate response?

  1. Keep all cases because different wording always means different tests
  2. Evaluate whether the cases provide distinct coverage before retaining them
  3. Delete the entire test suite
  4. Generate even more identical cases

Correct Answer: 2

Explanation

Different wording does not necessarily represent different testing value. The tester should compare the conditions, inputs, actions, expected results, and coverage of the cases. If they exercise essentially the same behavior, some may be redundant and can be consolidated. If the cases differ in meaningful conditions or risks, retaining them may be justified. This review helps prevent test-suite growth without corresponding increases in coverage. GenAI can easily produce multiple variations of a similar scenario, so testers should evaluate semantic uniqueness rather than relying on textual differences. The objective is a useful and maintainable test suite rather than the largest possible number of generated cases.

Question 338

A tester uses GenAI to generate automation code and wants to ensure the generated code does not introduce insecure practices. What should be performed?

  1. A security-focused code review of the generated code
  2. Only a spelling check
  3. Only a line-count comparison
  4. No review if the code executes successfully

Correct Answer: 1

Explanation

Generated automation code should undergo security review because GenAI may introduce insecure practices such as hard-coded credentials, unsafe commands, excessive permissions, insecure dependencies, or improper handling of sensitive data. Successful execution does not demonstrate that the code is secure. A security-focused review should consider the project’s coding standards, credential management, dependencies, permissions, data handling, and interaction with external systems. Automated security tools may provide additional checks, but human review remains valuable for contextual risks. Treating generated code as untrusted until reviewed helps reduce the possibility that insecure patterns will become part of the testing infrastructure.

Question 339

A tester wants to determine whether a generated test actually covers a requirement. Which question is most useful?

  1. Does the test verify behavior explicitly described by the requirement?
  2. Is the test description longer than the requirement?
  3. Was the test generated in less than one minute?
  4. Does the test contain advanced terminology?

Correct Answer: 1

Explanation

Coverage should be assessed by determining whether the test verifies behavior, conditions, or constraints described by the relevant requirement. A long description or sophisticated terminology does not demonstrate meaningful coverage. Generation speed is a productivity measure rather than a coverage measure. The tester should also check whether the expected result accurately represents the requirement and whether important conditions are missing. Traceability links can support this evaluation by connecting the test to an approved requirement identifier. GenAI can assist with identifying possible mappings, but testers should verify that the actual test behavior corresponds to what the requirement specifies.

Question 340

A testing organization wants to continuously improve its use of GenAI. Which practice would provide useful feedback?

  1. Ignore problems in generated outputs
  2. Record recurring output issues and refine prompts, controls, or review practices
  3. Accept every generated artifact without modification
  4. Measure only the amount of generated text

Correct Answer: 2

Explanation

Tracking recurring problems can help an organization improve its GenAI-assisted testing process. Issues such as repeated hallucinations, missing scenarios, inconsistent terminology, insecure code, poor formatting, or outdated assumptions can reveal opportunities to improve prompts, source context, model selection, validation procedures, or governance controls. Simply counting generated text does not indicate whether the process is effective. Similarly, accepting all generated artifacts removes an important quality-control mechanism. Continuous improvement should be based on observed results and defined quality criteria. This allows teams to increase the practical value of GenAI while reducing recurring risks in test design, automation, documentation, and analysis.