View Full ISTQB CT-GenAI Exam Dumps and Practice Test Dumps.
Question 141
A tester asks a GenAI model to generate test scenarios for a mobile banking application. Which information would most improve the relevance of the generated scenarios?
- The preferred font used in reports
- The tester’s favorite programming language
- The application’s key features, user roles, and testing scope
- The number of words required in the explanation
Correct Answer: 3
Explanation
Providing relevant context helps a GenAI model generate test scenarios that are aligned with the actual system and testing objectives. For a mobile banking application, information such as supported features, user roles, authentication mechanisms, transaction types, and testing scope can guide the model toward meaningful scenarios. Without this context, the model may make assumptions or generate generic tests that do not reflect the application’s behavior. Details such as report font, tester preferences, or explanation length may affect presentation but do not provide important domain information. The tester should still validate the generated scenarios against approved requirements and risk areas before using them in the testing process.
Question 142
Which GenAI technique is most appropriate when a tester wants the model to respond from the perspective of a security test analyst?
- Role prompting
- Data anonymization
- Tokenization
- Regression testing
Correct Answer: 1
Explanation
Role prompting instructs a GenAI model to adopt a particular perspective or professional role when producing an answer. For example, a tester might ask the model to act as a security test analyst and identify authentication, authorization, input-validation, and session-management scenarios. This can help focus the generated response on the desired viewpoint. However, role prompting does not guarantee that the model possesses expert-level knowledge or that its recommendations are correct. Generated security suggestions should still be reviewed by qualified testers and compared with applicable requirements and security standards. Data anonymization addresses sensitive information, tokenization concerns text representation, and regression testing is a testing activity rather than a prompting technique.
Question 143
A GenAI-generated test case includes an expected result that contradicts the approved requirement. What is the most appropriate action?
- Keep the test because GenAI may know a better behavior
- Remove the requirement from the test documentation
- Execute both behaviors and select whichever passes
- Correct or reject the generated test case based on the approved requirement
Correct Answer: 4
Explanation
Approved requirements provide the authoritative basis for determining expected system behavior. If a generated test case contradicts an approved requirement, the tester should not accept the generated expectation simply because it appears plausible. The case should be corrected or rejected according to the approved specification. If the requirement itself appears incorrect or outdated, the appropriate stakeholders should review and formally change it before the test basis is updated. Executing conflicting tests and choosing whichever result is convenient does not establish correctness. GenAI can assist with test design, but generated content remains subject to human review, organizational processes, and authoritative project documentation.
Question 144
What is a major limitation of using GenAI to generate complete test coverage automatically?
- GenAI cannot produce test cases for software
- Generated cases may miss important scenarios or contain incorrect assumptions
- GenAI always produces only positive test cases
- Generated tests cannot contain expected results
Correct Answer: 2
Explanation
GenAI can generate a large number of test cases, but quantity does not guarantee complete coverage. The model may overlook important business rules, unusual combinations, security risks, boundary conditions, integration scenarios, or non-functional requirements. It may also introduce assumptions that are not supported by the actual system. Therefore, testers should evaluate generated cases against requirements, risks, coverage objectives, and domain knowledge. GenAI can be valuable for expanding test ideas and identifying variations, but it should not be treated as an automatic proof of complete coverage. Human expertise and other systematic test-design techniques remain important when determining whether relevant testing objectives have been adequately addressed.
Question 145
A tester provides an existing test case and asks GenAI to rewrite it in a standardized format while preserving its meaning. Which task is this?
- Text transformation
- Model training
- Data poisoning
- Prompt injection
Correct Answer: 1
Explanation
Rewriting an existing test case into a standardized format while preserving its meaning is an example of text transformation. GenAI can assist with activities such as converting test cases into templates, improving wording, restructuring documentation, or changing the presentation format. The tester should verify that the transformation has not accidentally changed important conditions, steps, or expected results. Model training involves developing or adapting a model, while data poisoning refers to manipulating training data to influence model behavior. Prompt injection is an attack or manipulation technique that attempts to influence an AI system through crafted instructions. These concepts are different from ordinary transformation of testing content.
Question 146
A tester uses GenAI to generate SQL queries for database testing. What is an important security consideration before executing the generated queries?
- Assume generated SQL is safe because it came from an AI tool
- Remove all database restrictions
- Review the queries and execute them in an appropriately controlled environment
- Use production credentials to obtain realistic results
Correct Answer: 3
Explanation
Generated code can contain syntax errors, unintended operations, inefficient queries, or potentially dangerous database commands. Therefore, SQL generated by GenAI should be reviewed and tested in an appropriately controlled environment before execution. The tester should understand what each query does, verify the target database, restrict permissions, and use suitable test data. Production credentials should not be used unnecessarily, and database restrictions should not be removed merely to make testing easier. AI-generated code should be treated as untrusted until reviewed. Human validation is particularly important for commands that modify or delete data, access sensitive information, or interact with environments where mistakes could have significant consequences.
Question 147
Which statement best describes the relationship between GenAI-generated test data and production data?
- Synthetic data is always identical to production data
- Production data can always be copied directly into GenAI prompts
- GenAI automatically makes all production data anonymous
- Generated synthetic data can be designed to resemble realistic patterns without directly exposing actual records
Correct Answer: 4
Explanation
Synthetic test data can be designed to reproduce useful characteristics of real-world data without directly copying actual customer or production records. For example, a tester may need realistic transaction amounts, account structures, dates, or user profiles for testing. GenAI can help create such data, but the generated information should still be reviewed for validity and suitability. Production data should not automatically be submitted to an AI service because it may contain personal, confidential, or proprietary information. Synthetic data does not guarantee perfect representation of production conditions, but it can reduce unnecessary exposure of sensitive records while providing useful inputs for controlled testing.
Question 148
A tester notices that GenAI repeatedly generates similar test cases and misses uncommon combinations of conditions. What should the tester consider?
- The need for additional context, examples, or targeted prompts
- Increasing the font size of the generated output
- Removing all requirements from the prompt
- Assuming the uncommon combinations are not testable
Correct Answer: 1
Explanation
GenAI may focus on common or obvious patterns, especially when the prompt does not emphasize unusual combinations or provide sufficient context. A tester can improve the output by explicitly requesting pairwise or combinational scenarios, edge cases, negative conditions, risk-based scenarios, or examples of uncommon situations. Additional domain information and carefully selected examples may also help the model identify scenarios that were previously missed. However, improved prompting does not guarantee complete coverage. The tester should compare generated cases with established test-design techniques and coverage objectives. Uncommon combinations may be important, particularly when interactions between conditions can create significant defects or risks.
Question 149
What is the primary purpose of an embedding in many GenAI systems?
- To execute software automatically
- To represent information as numerical vectors that capture relationships or meaning
- To replace all test documentation
- To guarantee factual accuracy
Correct Answer: 2
Explanation
An embedding represents information such as text as a numerical vector in a way that can capture relationships and semantic similarities. Embeddings are commonly used in systems that need to retrieve relevant information, compare pieces of content, or provide context to a generative model. For example, a testing assistant may use embeddings to help locate requirements or documentation that are semantically related to a tester’s query. Embeddings do not execute software, replace documentation, or guarantee that generated information is factually correct. Their usefulness depends on the system architecture and the quality of the underlying information. Testers should still validate outputs against authoritative sources.
Question 150
A tester asks a GenAI model to identify missing test cases from an existing suite. Which approach provides the strongest basis for evaluating the response?
- Count only how many new test cases were generated
- Accept all cases that have detailed descriptions
- Compare the suggestions against requirements, risks, and existing coverage
- Select the longest generated test cases
Correct Answer: 3
Explanation
Identifying missing tests requires more than measuring the number or length of generated suggestions. The tester should compare the suggestions with approved requirements, identified risks, existing test coverage, business rules, interfaces, and relevant test conditions. This helps determine whether the generated cases actually address gaps rather than simply duplicating existing tests or introducing irrelevant scenarios. A detailed test case can still be unnecessary or incorrect. Similarly, generating many cases does not demonstrate improved coverage. GenAI can be useful for highlighting possible gaps, but systematic evaluation remains necessary. Human testers should determine whether the suggested scenarios correspond to genuine uncovered conditions and testing objectives.
Question 151
Which action is most appropriate when a GenAI model produces a confident answer that cannot be verified against any trusted source?
- Treat the confidence of the response as proof
- Present the answer as an established fact
- Use it without review because the wording is professional
- Mark it as unverified and seek supporting evidence
Correct Answer: 4
Explanation
A confident or fluent GenAI response does not establish that the information is correct. If an important statement cannot be verified against a trusted source, the tester should treat it as unverified rather than presenting it as established fact. Depending on the situation, supporting evidence may come from approved requirements, technical documentation, source code, system behavior, logs, standards, or subject-matter experts. This approach reduces the risk of hallucinated information entering testing artifacts or decisions. The tester should be particularly cautious when generated information affects security, compliance, expected behavior, or defect analysis. Verification is therefore more important than the model’s apparent confidence.
Question 152
A tester wants GenAI to produce test cases using a fixed structure containing ID, preconditions, steps, expected result, and priority. Which prompt feature is most relevant?
- Output-format instruction
- Random sampling
- Model retraining
- Data deletion
Correct Answer: 1
Explanation
An output-format instruction explicitly tells the GenAI model how the requested response should be structured. By specifying fields such as test ID, preconditions, steps, expected result, and priority, the tester can encourage consistent test-case formatting. This makes generated content easier to review, compare, and potentially transfer into testing tools. A format instruction does not guarantee that the values placed in those fields are correct, so the generated cases still require validation. Random sampling relates to how data or outputs may be selected, model retraining concerns changing or adapting a model, and data deletion concerns removing information. None directly addresses the requested structure of generated test cases.
Question 153
Why should testers be cautious when using GenAI to interpret requirements containing domain-specific terminology?
- The model cannot process technical words
- The model may misunderstand specialized terms without sufficient context
- Domain terminology automatically causes prompt injection
- Specialized terminology prevents all test generation
Correct Answer: 2
Explanation
Domain-specific terminology can have meanings that differ from ordinary language or from other industries. Without sufficient context, a GenAI model may interpret specialized terms incorrectly and generate test cases based on an incorrect understanding. Providing definitions, relevant documentation, examples, or approved terminology can help reduce this risk. Even with additional context, the tester should verify the interpretation against authoritative project information. GenAI is capable of processing technical language, so the presence of specialized terms does not prevent test generation. The key concern is semantic accuracy. Incorrect interpretation of domain concepts can lead to unsuitable test conditions, incorrect expected results, and gaps in coverage.
Question 154
Which scenario is an example of prompt injection affecting a GenAI-based testing assistant?
- A tester requests five regression tests
- A tester provides a requirement with acceptance criteria
- Untrusted input contains instructions attempting to override the assistant’s original testing instructions
- A tester asks for test cases in table format
Correct Answer: 3
Explanation
Prompt injection occurs when content supplied to a GenAI system contains instructions intended to manipulate the model into ignoring or overriding its original instructions or intended task. In a testing assistant, untrusted requirements, documentation, web content, tickets, or other inputs could contain text that attempts to change the assistant’s behavior. This is especially important when an AI system processes external or user-controlled content. Testers and system designers should consider trust boundaries, input handling, instruction hierarchy, access controls, and output validation. A normal request for regression tests, acceptance criteria, or a specific output format is not itself prompt injection unless it attempts to manipulate the system improperly.
Question 155
A tester uses GenAI to generate regression tests after a change to a payment component. What additional information would help the model focus the generated tests?
- The color of the application’s logo
- The tester’s personal preferences
- The complete history of unrelated projects
- The changed functionality, affected interfaces, dependencies, and relevant requirements
Correct Answer: 4
Explanation
Regression-test generation benefits from information about what changed and what could be affected by that change. For a payment component, useful context may include modified functionality, affected APIs, dependencies, business rules, integration points, and relevant requirements. This information helps the model identify areas that may require retesting and related scenarios that could have been impacted. Irrelevant project history and personal preferences do not provide useful testing context. The generated regression tests should still be compared with the existing test suite and change impact analysis. GenAI can help identify potential regression scenarios, but testers remain responsible for deciding which tests are appropriate for the actual system and change.
Question 156
Which factor is particularly important when evaluating whether GenAI-generated test cases are suitable for use?
- The number of emojis in the response
- Correctness, relevance, completeness, and alignment with requirements
- The length of the model’s system prompt alone
- Whether the response sounds confident
Correct Answer: 2
Explanation
The suitability of GenAI-generated test cases should be evaluated using meaningful quality criteria. Correctness determines whether the test accurately represents expected behavior. Relevance determines whether it addresses the intended scope. Completeness considers whether important conditions or scenarios are missing, while alignment with requirements ensures that the test is based on approved expectations. A confident tone or long response does not establish quality. Similarly, superficial characteristics of the prompt do not demonstrate that generated tests are suitable. Depending on the testing context, additional criteria such as traceability, maintainability, security, consistency, and feasibility may also be relevant. Human review is needed to assess these factors before adoption.
Question 157
A GenAI model generates an automation script containing a library that is not approved by the organization. What should the tester do?
- Use it immediately because the library was suggested by the model
- Install the library on every tester’s machine
- Replace or evaluate the dependency according to organizational standards
- Disable dependency scanning
Correct Answer: 3
Explanation
Generated automation code may introduce libraries or dependencies that have not been approved for organizational use. The tester should review the dependency and follow established processes for evaluating, approving, replacing, or removing it. Considerations may include security, licensing, maintenance, compatibility, vulnerabilities, and organizational standards. Installing an unapproved dependency simply because an AI model suggested it can introduce unnecessary technical or security risk. Dependency scanning and other controls should remain enabled rather than being disabled. GenAI can accelerate code creation, but generated code and dependencies must still comply with the same governance and engineering requirements applied to manually created automation.
Question 158
What is one reason why a tester should preserve the original requirements when using GenAI for test design?
- To provide an authoritative basis for validating generated tests
- To prevent the model from generating any negative tests
- To guarantee that the model will never hallucinate
- To eliminate the need for human review
Correct Answer: 1
Explanation
Approved requirements provide an authoritative basis against which generated test cases can be evaluated. By preserving the original requirements, testers can check whether generated scenarios correctly represent expected behavior, identify missing conditions, and establish traceability between requirements and tests. This comparison can also reveal when GenAI has introduced unsupported assumptions or misunderstood a requirement. Keeping requirements does not prevent hallucinations or guarantee complete test generation, and it does not remove the need for human review. Instead, requirements provide essential context and evidence for evaluating the usefulness and correctness of generated testing artifacts. This is especially important when generated content is later incorporated into formal test documentation.
Question 159
A tester asks GenAI to generate tests for a feature that has both functional and performance requirements. What should the tester ensure?
- Only functional behavior is considered
- The model creates as many functional tests as possible
- Performance requirements are ignored because they are non-functional
- Both functional behavior and applicable performance criteria are represented
Correct Answer: 4
Explanation
Testing objectives can include both functional and non-functional requirements. If a feature has functional requirements and performance criteria, the generated test strategy should address both where applicable. Functional tests may verify that the feature performs the required operations correctly, while performance tests may examine response time, throughput, resource usage, or other defined measures. Ignoring performance requirements can leave important risks untested. Simply generating more functional tests does not compensate for missing non-functional coverage. The tester should provide GenAI with the relevant requirements and clearly specify the desired testing scope. Generated tests should then be reviewed to confirm that the applicable criteria are measurable and accurately represented.
Question 160
Which practice best supports responsible use of GenAI in a software testing team?
- Allowing the model to make all testing decisions independently
- Combining appropriate AI assistance with human oversight, validation, and accountability
- Using generated content without recording its source
- Avoiding all review because AI improves productivity
Correct Answer: 2
Explanation
Responsible use of GenAI requires balancing the benefits of automation and assistance with appropriate human oversight. Testers can use GenAI to accelerate activities such as test generation, documentation, analysis, and automation development, but important outputs should be validated according to their risk and purpose. The team should also consider privacy, security, intellectual property, traceability, accuracy, and organizational governance. Allowing a model to make all testing decisions removes necessary accountability, while avoiding review can allow incorrect or unsafe content to enter the testing process. A responsible approach defines suitable uses, establishes review practices, protects sensitive information, and keeps humans accountable for important testing decisions.