ISTQB CT-GenAI Practice Test Questions and Exam Dumps Part16 Q301-320

View Full ISTQB CT-GenAI Exam Dumps and Practice Test Dumps.

 

Question 301

A tester asks GenAI to generate tests for a requirement but does not provide any information about the feature’s scope. What is the most likely risk?

  1. The model may generate scenarios outside the intended testing scope
  2. The model will automatically identify the correct scope
  3. The model will refuse to generate any tests
  4. The model will guarantee complete coverage

Correct Answer: 1

Explanation

Scope information helps GenAI understand which functionality should and should not be considered when generating tests. Without clear scope, the model may produce scenarios for unrelated features, unsupported integrations, or behavior that is not part of the current release. This can increase review effort and create misleading test coverage. Providing relevant requirements, exclusions, user roles, and constraints can improve the focus of generated output. The tester should still review the resulting cases against the approved scope. GenAI can assist with test design, but it does not automatically know project boundaries unless those boundaries are provided through reliable context.

Question 302

Which approach is most appropriate when using GenAI to generate tests for a frequently changing software feature?

  1. Use only historical requirements
  2. Provide the current approved requirements and verify generated tests against them
  3. Ignore recent changes because the model already knows the feature
  4. Generate tests without any version information

Correct Answer: 2

Explanation

Frequently changing features require current information because older requirements or examples may no longer represent actual behavior. The tester should provide the current approved requirements and relevant version information and then validate generated tests against those sources. Relying on historical information can result in obsolete scenarios, incorrect expected results, or missing newly introduced conditions. GenAI should not be assumed to know the latest project-specific changes. Version-aware prompting and human review help maintain alignment between generated tests and the current product state. This is particularly important for regression testing, where outdated test assumptions can cause unnecessary failures or missed defects.

Question 303

A tester receives a GenAI-generated test case containing a claim about application behavior that cannot be verified from available documentation. What should the tester do?

  1. Treat the claim as confirmed behavior
  2. Include the claim in the approved requirements
  3. Mark the claim for verification and seek authoritative evidence
  4. Remove all documentation from the testing process

Correct Answer: 3

Explanation

An unverifiable claim should not automatically be treated as fact. The tester should identify the claim and verify it against authoritative requirements, technical documentation, product behavior, or an appropriate subject-matter expert. If the claim cannot be confirmed, it should not be used as an established expected behavior. GenAI can generate plausible statements that are unsupported by the available evidence, which is one reason human validation is important. Recording uncertain information as confirmed behavior can create incorrect tests and misleading results. A controlled verification process helps separate generated suggestions from facts that have been established by reliable project sources.

Question 304

A team wants to use GenAI to generate regression tests after a small code change. Which information is particularly useful to provide?

  1. Only the developer’s name
  2. The change details, affected components, and relevant existing tests
  3. The project logo
  4. The total number of employees

Correct Answer: 2

Explanation

Regression-test selection benefits from understanding what changed and which components may have been affected. Providing change details, affected modules, interfaces, dependencies, and existing tests gives GenAI useful context for suggesting relevant regression scenarios. The generated suggestions should then be reviewed against impact analysis and actual system dependencies. Personal information about the developer or unrelated organizational information does not meaningfully support test selection. Existing tests can also help identify areas already covered and potential gaps. GenAI can accelerate the identification of candidate regression tests, but testers should confirm that the selected tests appropriately reflect the actual change and associated risks.

Question 305

A tester asks GenAI to generate tests from an approved specification and notices that the model adds an extra business rule that is not documented. What is this an example of?

  1. Requirements traceability
  2. Test execution
  3. Requirement hallucination or unsupported assumption
  4. Boundary-value analysis

Correct Answer: 4

Explanation

Adding an undocumented business rule is an example of unsupported generated content. GenAI may produce plausible requirements or rules that were not present in the supplied specification. The tester should identify the added rule and verify whether it exists in an authoritative source. If it does not, it should not be treated as an actual requirement. This distinction is important because generated assumptions can lead to incorrect expected results and unnecessary test cases. Requirements traceability helps establish what behavior is actually approved, while hallucination or unsupported assumptions represent generated information that lacks sufficient evidence.

Question 306

A tester is reviewing GenAI-generated tests for a password-reset feature. Which scenario is particularly relevant to negative testing?

  1. A user successfully resets a password using valid information
  2. A user requests a reset using an invalid or expired reset token
  3. A user opens the password-reset page
  4. A user enters a valid email address

Correct Answer: 1

Explanation

Negative testing examines how the system behaves when invalid, unexpected, or unauthorized conditions occur. An expired or invalid reset token is therefore an important negative scenario for a password-reset feature. A successful reset with valid information represents positive testing, while opening the page or entering a valid email address does not necessarily exercise an error condition. GenAI can help identify additional negative scenarios, such as reused tokens, malformed requests, excessive attempts, or unauthorized access. These suggestions should be checked against the application’s approved security and functional requirements before being incorporated into the test suite.

Question 307

A tester wants GenAI to produce test cases using the same terminology as an organization’s approved glossary. What should the tester provide?

  1. The approved glossary or relevant terminology definitions
  2. Random examples from unrelated projects
  3. Only the model name
  4. No terminology information

Correct Answer: 2

Explanation

Providing an approved glossary helps GenAI use terminology consistently with the organization’s established language. This is particularly useful in complex domains where similar words may have different meanings or where specific business terms must be used consistently across requirements and test artifacts. Random examples from unrelated projects can introduce conflicting terminology and assumptions. The generated output should still be reviewed to ensure that the terminology is used correctly in context. A glossary can improve consistency, readability, and traceability, but it does not guarantee that every generated statement is factually correct. Human review remains necessary before formal use.

Question 308

A tester asks GenAI to create test cases and specifies that every case must include preconditions, steps, test data, and expected results. What is the main benefit of this instruction?

  1. It guarantees complete functional coverage
  2. It establishes a consistent output structure
  3. It eliminates hallucinations
  4. It removes the need for test review

Correct Answer: 3

Explanation

Explicitly defining required fields establishes a consistent structure for generated test cases. This makes the output easier to review, compare, and potentially transfer into test-management tools. However, structured output does not guarantee complete coverage or eliminate hallucinations. A test can contain all requested fields while still having incorrect steps, invalid data, or unsupported expected results. Human review is therefore still required. Structured prompting is best viewed as a way to improve consistency and usability rather than as a substitute for professional validation. Testers should evaluate both the format and the substantive correctness of the generated cases.

Question 309

A tester wants to evaluate whether GenAI-generated tests identify important edge cases. Which comparison would be most useful?

  1. Compare the generated tests with known risks, boundary conditions, and relevant requirements
  2. Compare only the number of words
  3. Compare the font used in each test
  4. Compare only the test-case titles

Correct Answer: 1

Explanation

Edge-case coverage should be evaluated against information that identifies where unusual or high-risk behavior may occur. Requirements, boundary conditions, known risks, error conditions, and business rules provide a meaningful basis for comparison. Simply counting words or comparing titles does not establish whether important edge cases are represented. The tester can use GenAI to suggest additional unusual scenarios, but each suggestion should be checked for relevance and feasibility. A systematic comparison can reveal missing conditions that may not be obvious from common user journeys. This helps ensure that GenAI contributes useful breadth rather than merely producing more test cases.

Question 310

A GenAI-generated test script uses an external library that is not approved for the project. What should the tester do?

  1. Install the library immediately
  2. Ignore the dependency because the script works
  3. Verify whether the dependency is permitted and replace or remove it if necessary
  4. Add the library to production automatically

Correct Answer: 4

Explanation

Generated code can introduce dependencies that are not approved by the organization’s technology, security, licensing, or architecture policies. The tester should verify the dependency against the project’s approved technology stack and governance requirements before using it. If the library is not permitted, the code should be modified to use an approved alternative or avoid the dependency. A script working technically does not make an unapproved dependency acceptable. GenAI-generated code should therefore be reviewed for more than syntax and functionality. Dependency management, security, licensing, and maintainability are all relevant when generated automation becomes part of a controlled testing environment.

Question 311

Which action best helps a tester detect whether GenAI has omitted a requirement when generating a test suite?

  1. Compare the generated tests against a requirements-to-test traceability matrix
  2. Count the number of generated tests
  3. Ask the model to confirm that nothing was missed
  4. Review only the first generated test

Correct Answer:2

Explanation

A requirements-to-test traceability matrix provides a structured way to compare approved requirements with test coverage. If a requirement has no corresponding test or objective, the tester can investigate whether coverage is missing or intentionally excluded. Simply counting generated tests does not show whether the right requirements are covered because many tests may address the same requirement. Asking the model to confirm completeness is also insufficient because the model may overlook its own omissions. Traceability therefore provides stronger evidence for identifying gaps. The tester should review missing or questionable mappings against the approved requirements and project scope before finalizing the test suite.

Question 312

A tester asks GenAI to create a test summary for senior management. Which adaptation is most appropriate?

  1. Include every technical log line
  2. Focus on concise results, significant risks, major defects, and overall test status
  3. Remove all information about risks
  4. Use only raw automation code

Correct Answer: 3

Explanation

Senior management generally needs concise information that supports understanding of overall testing status and significant project risks. A summary can therefore focus on major results, important defects, outstanding risks, scope, and relevant limitations rather than reproducing detailed technical logs. The exact content should reflect the organization’s reporting requirements and the audience’s needs. GenAI can help transform verified execution information into a suitable format, but the tester must verify all figures and statements before publication. Removing risk information entirely can make the summary misleading, while raw logs or automation code are usually inappropriate as the primary management-level communication.

Question 313

A tester uses GenAI to generate test data containing names, addresses, and account numbers. Which issue should be checked before the data is used?

  1. Whether the generated data complies with applicable privacy and data-handling requirements
  2. Whether the names are alphabetically ordered
  3. Whether the model used a short response
  4. Whether every record has the same account number

Correct Answer: 4

Explanation

Generated test data containing personal or account-related information should be evaluated for privacy, security, and organizational data-handling requirements. The tester should determine whether the values are synthetic, whether they accidentally reproduce real information, and whether their use is authorized. Appropriate controls should also be applied to storage and sharing. The exact structure and realism of the data should match the testing objective. Simple characteristics such as alphabetical ordering are usually secondary. GenAI-generated data should not automatically be assumed to be safe merely because it was created artificially. Validation is needed to ensure that the data is both suitable for testing and appropriately protected.

Question 314

A tester provides GenAI with a detailed prompt containing the feature context, test objective, constraints, and expected output format. What is the primary purpose of including these elements together?

  1. To make the prompt longer than necessary
  2. To prevent all possible model errors
  3. To give the model sufficient guidance for producing task-relevant output
  4. To remove the need for requirements

Correct Answer: 1

Explanation

A well-structured prompt provides the model with context, purpose, constraints, and output expectations. These elements help GenAI understand what task it is performing and what type of response is useful. The goal is not simply to make the prompt longer, but to provide relevant information that reduces ambiguity. Even a detailed prompt cannot guarantee that the output will be correct or complete. Requirements remain authoritative and must continue to guide testing decisions. Clear prompting can improve the quality and consistency of generated content, while validation ensures that the output actually meets the project’s testing objectives.

Question 315

A tester asks GenAI to identify security test scenarios for an administrator function. Which scenario should be considered?

  1. An unauthorized user attempts to access an administrator-only operation
  2. An authorized administrator logs in successfully
  3. A user views the public home page
  4. A user reads publicly available documentation

Correct Answer: 3

Explanation

Security testing should consider unauthorized access and attempts to bypass established controls. An unauthorized user attempting an administrator-only operation is therefore an important security scenario. Successful administrator login is useful for positive authorization testing but does not directly exercise an unauthorized condition. Public pages and documentation generally do not test the protected administrative control. GenAI can help generate additional security scenarios, including privilege escalation, session issues, improper access after logout, and unauthorized API requests. The generated cases should be validated against approved security requirements and application architecture before execution.

Question 316

A team wants GenAI to generate test cases for a feature with complex business rules. Which approach can improve output quality?

  1. Provide representative examples and clearly state the relevant business rules
  2. Hide the business rules from the model
  3. Ask for tests without explaining the feature
  4. Encourage the model to invent missing rules

Correct Answer: 2

Explanation

Complex business rules require sufficient context for GenAI to generate meaningful scenarios. Providing representative examples and explicit rules helps the model understand valid combinations, restrictions, exceptions, and expected outcomes. Without this information, the model may produce generic or incorrect tests. Asking it to invent missing rules creates unsupported assumptions that can compromise test accuracy. Examples should be accurate, relevant, and free from unauthorized sensitive information. Even when business rules are clearly provided, generated cases must be compared with the approved specification and reviewed by knowledgeable testers. This combination of context, examples, and validation can improve the usefulness of GenAI-assisted test design.

Question 317

A tester discovers that a GenAI-generated automation script logs sensitive test credentials to the console. What should the tester do?

  1. Keep the logging because it helps debugging
  2. Remove or protect the sensitive logging and review the script for similar issues
  3. Publish the script unchanged
  4. Add more sensitive information to the logs

Correct Answer: 4

Explanation

Sensitive credentials should not normally be written to logs because logs may be accessible to multiple users or retained for extended periods. The tester should remove the credential logging or replace it with safe diagnostic information and review the script for similar security problems. GenAI-generated code can reproduce insecure patterns from examples or make unsafe implementation choices, so security review is necessary before execution in controlled environments. Debugging requirements should be satisfied without exposing secrets. Appropriate secret-management mechanisms and masking practices should be used where applicable. Generated automation should meet the same security standards as manually written test code.

Question 318

Which activity is an appropriate use of GenAI during exploratory testing?

  1. Generating possible questions and unusual scenarios for the tester to investigate
  2. Making final release decisions without human review
  3. Declaring all generated defects to be confirmed
  4. Replacing all tester observation

Correct Answer: 3

Explanation

GenAI can support exploratory testing by suggesting questions, unusual combinations, edge cases, alternative workflows, and areas that may deserve investigation. The tester then uses professional judgment and direct observation to explore the application. Generated suggestions are not automatically confirmed defects or final conclusions. Exploratory testing benefits from human learning and adaptation as new information emerges during execution. GenAI can broaden the tester’s perspective, but it should remain an assisting tool rather than the sole decision-maker. This approach allows teams to benefit from rapid idea generation while preserving human responsibility for observations, interpretations, and final findings.

Question 319

A tester receives a GenAI-generated test suite with excellent functional coverage but no tests for authentication failures. What should the tester conclude?

  1. The suite is automatically complete because functional coverage is high
  2. Authentication testing is unnecessary
  3. The missing security-related scenarios should be assessed against applicable requirements and risks
  4. The functional tests should all be deleted

Correct Answer: 1

Explanation

High functional coverage does not automatically mean that the overall test suite is complete. Authentication failures may represent an important security requirement or risk and should be considered separately from ordinary functional coverage. The tester should examine security requirements, threat information, risk assessments, and relevant system behavior to determine whether authentication failure scenarios are required. GenAI-generated suites can emphasize common functional workflows while overlooking security conditions. Coverage should therefore be evaluated across relevant dimensions rather than relying on a single metric. Missing authentication tests may represent an important gap even when the generated functional scenarios appear comprehensive.

Question 320

A testing team wants to improve its GenAI prompts after repeatedly receiving incomplete test cases. Which action is most appropriate?

  1. Analyze the missing information and refine the prompts with clearer requirements, constraints, and examples
  2. Increase the number of generated cases without changing the prompt
  3. Remove all requirements from the prompts
  4. Accept the incomplete cases as normal

Correct Answer: 2

Explanation

Repeated omissions can indicate that the prompt does not provide enough context, constraints, examples, or explicit coverage expectations. The team should analyze the missing scenarios and refine the prompting approach accordingly. This may involve adding relevant requirements, specifying the testing objective, identifying important conditions, providing representative examples, or defining the desired output structure. Simply generating more cases may increase volume without addressing the underlying omission. Removing requirements would further reduce useful context. Prompt refinement should be iterative and evidence-based, with generated outputs evaluated against known expectations to determine whether the changes actually improve completeness and relevance.