{"id":25062,"date":"2026-09-30T11:34:56","date_gmt":"2026-09-30T11:34:56","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=25062"},"modified":"2026-09-30T11:34:56","modified_gmt":"2026-09-30T11:34:56","slug":"istqb-ct-genai-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/istqb-ct-genai-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"ISTQB CT-GenAI Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ct-genai-exam-dumps\"><b>ISTQB CT-GenAI Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 21<\/b><\/h3>\n<p><b>Which characteristic of a large language model is most relevant when a tester uses it to generate test cases from a natural-language requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It always produces identical output for the same prompt<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It can generate text based on patterns learned from training data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It can directly execute every generated test case<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It guarantees complete requirements coverage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Large language models generate text by using patterns learned from their training data and the context supplied in the prompt. This capability allows testers to ask the model to create possible test cases from natural-language requirements. However, generation does not guarantee that every requirement, boundary condition, or business rule will be covered. The model also does not automatically execute the generated tests or guarantee their correctness. Therefore, testers should review generated test cases for accuracy, relevance, completeness, and alignment with the actual requirements before using them in a testing process.<\/span><\/p>\n<h3><b>Question 22<\/b><\/h3>\n<p><b>A tester asks a GenAI tool to create boundary value test cases but provides no information about the valid input range. What is the most likely problem?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The model will automatically know the correct business limits<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The model will refuse every testing request<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The generated cases may use inappropriate or assumed boundaries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The model will execute the boundary tests automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Boundary value analysis depends on knowing the valid and invalid limits of an input. If those limits are not included in the prompt or available through reliable context, a GenAI tool may make assumptions about the boundaries. These assumptions can result in test cases that do not correspond to the actual business rules. A tester should therefore provide the relevant requirements, ranges, and constraints when asking GenAI to generate boundary-related tests. The generated results should then be checked against the authoritative specification to ensure that the selected boundary values are correct and meaningful.<\/span><\/p>\n<h3><b>Question 23<\/b><\/h3>\n<p><b>What is the main purpose of providing context in a prompt used for GenAI-assisted test design?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To make the model&#8217;s response independent of the requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent the model from generating any test cases<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To guarantee that the generated tests are defect-free<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To help the model produce outputs relevant to the testing situation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Context helps a GenAI system understand the specific testing situation in which an output is required. Relevant context can include requirements, business rules, application behavior, user roles, test objectives, constraints, and expected output formats. Without adequate context, generated test cases may be too generic or may make assumptions that do not apply to the system under test. Providing useful context does not guarantee correct or complete results, so testers still need to validate the generated artifacts. Good context generally improves relevance and reduces unnecessary assumptions in GenAI-generated testing content.<\/span><\/p>\n<h3><b>Question 24<\/b><\/h3>\n<p><b>Which prompting technique provides several examples of desired input and output behavior to a GenAI model?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Few-shot prompting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero-shot prompting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Random prompting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Negative prompting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Few-shot prompting provides the model with several examples that demonstrate the expected relationship between input and output. In software testing, a tester might provide multiple examples of requirements together with correctly structured test cases and then ask the model to generate additional cases in the same style. These examples can help clarify terminology, structure, and expected level of detail. Zero-shot prompting provides instructions without examples, while one-shot prompting normally provides one example. Few-shot prompting does not guarantee correctness, so generated results should still be reviewed against the requirements and testing objectives.<\/span><\/p>\n<h3><b>Question 25<\/b><\/h3>\n<p><b>A tester receives different test cases from the same GenAI prompt at different times. Which property of GenAI best explains this behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterministic execution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Probabilistic generation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requirements traceability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GenAI systems can produce different outputs from the same or very similar prompts because their generation process is probabilistic. Model settings, such as temperature, can also affect the variability of responses. This behavior means that a tester should not automatically assume that repeating a prompt will always produce exactly the same test cases. For important testing activities, outputs should be reviewed and, where necessary, controlled through appropriate prompts, configurations, validation procedures, and documentation. Reproducibility should be considered when GenAI-generated artifacts become part of a formal testing process.<\/span><\/p>\n<h3><b>Question 26<\/b><\/h3>\n<p><b>Which activity is most appropriate after a GenAI tool generates automated test code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediately deploy the code to production<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assume the code is correct because it was generated by a model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all human review from the process<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review, execute, and validate the generated code<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Generated automation code can contain syntax errors, incorrect assumptions, insecure practices, unsuitable locators, or logic that does not match the intended test objective. Therefore, generated code should be treated as an aid rather than automatically trusted production-ready code. A tester or developer should review the code, execute it in an appropriate environment, verify its behavior, and confirm that it provides the intended coverage. Additional checks may include coding standards, security requirements, maintainability, and integration with the existing automation framework. Human validation remains important even when the generated code appears plausible.<\/span><\/p>\n<h3><b>Question 27<\/b><\/h3>\n<p><b>What is a potential advantage of using GenAI to support exploratory testing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It can suggest test ideas and scenarios for investigation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It guarantees that all defects will be discovered<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It replaces all tester observation and judgment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It automatically determines business priorities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GenAI can support exploratory testing by suggesting alternative scenarios, unusual inputs, user behaviors, questions, or areas that deserve further investigation. These suggestions can help testers broaden their thinking and identify possibilities they may not have considered initially. However, GenAI cannot guarantee complete defect detection and should not replace the tester&#8217;s observation, domain knowledge, or judgment. The tester decides which suggestions are relevant and how they should be investigated. Exploratory testing still relies heavily on learning, investigation, and adaptation during the testing activity.<\/span><\/p>\n<h3><b>Question 28<\/b><\/h3>\n<p><b>A company wants to use customer production data as input to an external GenAI service for generating test cases. What should be considered first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the prompt is short enough<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the model can generate many test cases<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data privacy, confidentiality, and organizational policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the generated output contains exactly four options<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Production data may contain personal, confidential, proprietary, or otherwise sensitive information. Sending such data to an external GenAI service can create privacy, security, contractual, regulatory, or organizational risks. Before using production information, the organization should determine whether the data is permitted to be processed by the service and whether appropriate protections are in place. Data minimization, anonymization, masking, approved environments, and organizational policies may be relevant. The ability of the model to generate useful test cases is important, but it does not override privacy and security requirements.<\/span><\/p>\n<h3><b>Question 29<\/b><\/h3>\n<p><b>Which approach can help a tester improve a GenAI-generated test case when the first result is too general?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all context from the prompt<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Add relevant constraints and clarify the expected output<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accept the result without review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ask the model to ignore the requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a generated test case is too general, the tester can refine the prompt by adding relevant context, constraints, examples, business rules, or a specific output structure. For example, the tester could specify user roles, valid and invalid inputs, expected behavior, preconditions, and the number of test cases required. Iterative prompt refinement can make generated outputs more focused and useful. However, improved prompting does not guarantee correctness. The resulting test cases should still be compared with authoritative requirements and reviewed by a suitably knowledgeable tester before being incorporated into the test process.<\/span><\/p>\n<h3><b>Question 30<\/b><\/h3>\n<p><b>Which statement best describes a hallucination produced by a GenAI system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A response that is intentionally encrypted<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A response that contains only information from a database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A response that is always incomplete<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A plausible-looking response that contains inaccurate or unsupported information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hallucination occurs when a GenAI system produces information that may appear plausible or confidently stated but is inaccurate, unsupported, or fabricated. In testing, this can be particularly problematic when the model invents requirements, API behavior, test results, defects, or technical explanations. Testers should therefore verify important generated information against authoritative sources. Confidence or fluent wording is not evidence that the information is correct. Hallucination risk is one reason human review and independent validation remain necessary when GenAI is used to support software testing activities.<\/span><\/p>\n<h3><b>Question 31<\/b><\/h3>\n<p><b>Which GenAI capability can be useful when creating synthetic test data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Generating realistic variations of data according to specified characteristics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guaranteeing that synthetic data represents every production condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatically approving all generated data for production use<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminating the need to define test data requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GenAI can help testers generate synthetic data by creating realistic variations according to characteristics specified in the prompt. For example, it may produce different customer profiles, addresses, product descriptions, or combinations of input values. Synthetic data can be useful when real production data is inappropriate because of privacy or confidentiality concerns. However, generated data still needs validation. Testers should check that it satisfies the required format, business rules, boundary conditions, and test objectives. Synthetic data should not automatically be assumed to represent every possible real-world condition or distribution.<\/span><\/p>\n<h3><b>Question 32<\/b><\/h3>\n<p><b>A tester asks GenAI to summarize test execution results. What should the tester verify in the generated summary?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only its grammar and formatting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether it contains enough technical jargon<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether it accurately represents the underlying test results<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether it is longer than the original report<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A generated test summary should accurately reflect the underlying test execution information. The tester should verify important figures, passed and failed tests, blocked tests, significant defects, trends, and other reported findings against the original evidence. A fluent or well-formatted summary can still contain omissions or incorrect interpretations. Validation is therefore more important than presentation quality alone. The tester should also check whether important context or limitations were lost during summarization. GenAI can reduce the effort required to produce an initial summary, but responsibility for the accuracy of the final report remains with the appropriate human stakeholders.<\/span><\/p>\n<h3><b>Question 33<\/b><\/h3>\n<p><b>Which risk can arise when a tester becomes overly dependent on GenAI-generated testing ideas?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increased requirement traceability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduced independent thinking and critical analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guaranteed higher test coverage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elimination of testing bias<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Overdependence on GenAI can cause testers to accept generated suggestions without applying sufficient independent analysis. This may reduce critical thinking and make testers less likely to question assumptions, investigate unexpected behavior, or develop alternative testing approaches. GenAI can be valuable for brainstorming and accelerating repetitive tasks, but it should complement rather than replace professional judgment. Testers should continue to analyze requirements, understand risks, consider domain-specific scenarios, and challenge generated outputs. Maintaining human involvement helps ensure that testing decisions are based on evidence and appropriate knowledge of the system.<\/span><\/p>\n<h3><b>Question 34<\/b><\/h3>\n<p><b>What is the main purpose of a structured output format in a GenAI prompt for test case generation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent the model from using any testing terminology<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To make every generated test case automatically correct<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To specify how the requested information should be organized<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To eliminate the need for requirement analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A structured output format tells the GenAI system how the requested information should be organized. For example, a tester may request fields such as test case ID, objective, preconditions, steps, test data, and expected result. This can make generated outputs easier to review, compare, process, and integrate into existing workflows. A structured format does not guarantee that the information itself is correct or complete. Testers still need to validate the generated content against requirements and test objectives. Clear output instructions are particularly useful when many generated artifacts need consistent formatting.<\/span><\/p>\n<h3><b>Question 35<\/b><\/h3>\n<p><b>A tester wants GenAI to identify missing test scenarios from a set of requirements. Which additional information would generally improve the request?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Relevant business rules, risks, and testing objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An instruction to ignore edge cases<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An unrelated software license<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Only the name of the application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Providing business rules, known risks, testing objectives, and relevant system context can help GenAI identify more meaningful potential test scenarios. For example, requirements alone may not reveal which functions are considered high risk or which user roles have special permissions. Additional context helps the model focus its suggestions on the areas that matter to the testing objectives. Nevertheless, the generated scenarios should be reviewed for omissions and incorrect assumptions. A tester should also use established test analysis techniques and domain knowledge rather than relying solely on GenAI to determine whether coverage is sufficient.<\/span><\/p>\n<h3><b>Question 36<\/b><\/h3>\n<p><b>Which statement about GenAI-generated test cases is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They can be used without validation when the prompt is detailed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They are always superior to manually designed test cases<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They should be treated as suggestions requiring appropriate review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">They automatically provide complete requirements traceability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GenAI-generated test cases can provide useful suggestions and accelerate test design, but they should not automatically be considered authoritative. A detailed prompt can improve relevance, yet the model may still misunderstand requirements, omit important scenarios, or introduce incorrect assumptions. Testers should review generated cases for correctness, completeness, relevance, and traceability. Where appropriate, they should compare the cases with requirements and risk information. GenAI can therefore support human test design rather than completely replacing the analysis and judgment required from qualified testing professionals.<\/span><\/p>\n<h3><b>Question 37<\/b><\/h3>\n<p><b>What is one reason that generated test automation code may require additional security review?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The code may contain insecure implementation patterns or unsafe assumptions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Generated code can never contain syntax errors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security review is unnecessary for test environments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GenAI automatically follows every organizational security policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GenAI-generated code can contain insecure implementation patterns, inappropriate dependencies, weak handling of credentials, unsafe input processing, or assumptions that conflict with organizational security practices. Although test automation is not normally production application code, it can still interact with systems, credentials, databases, APIs, and sensitive environments. Therefore, generated automation should be reviewed and tested according to relevant coding and security requirements. Testers and developers should not assume that the model automatically understands or follows the organization&#8217;s specific security policies. Human review helps identify problems before generated code is incorporated into an automation framework.<\/span><\/p>\n<h3><b>Question 38<\/b><\/h3>\n<p><b>Which practice can help reduce the risk of exposing sensitive information when using GenAI for testing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Include all available production information in every prompt<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share credentials so the model understands the environment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use approved data-handling practices and minimize sensitive information<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all access controls before prompting the model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sensitive information should be handled according to organizational security and privacy requirements. Testers can reduce exposure by minimizing the data included in prompts, removing unnecessary personal information, anonymizing or masking sensitive values, and using approved GenAI services and environments. Credentials, secrets, and confidential information should not be shared simply to provide additional context. Data-handling controls should be established before GenAI is incorporated into testing workflows. These practices reduce the potential impact of accidental disclosure while still allowing testers to use GenAI for activities such as test design, data generation, and documentation.<\/span><\/p>\n<h3><b>Question 39<\/b><\/h3>\n<p><b>What does zero-shot prompting generally mean?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Providing no task description at all<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asking the model to perform a task without providing examples of the desired output<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Providing many examples before the task<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Providing exactly two examples and no instructions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero-shot prompting means asking a GenAI model to perform a task without supplying examples that demonstrate the desired input-output relationship. The tester may still provide clear instructions, context, constraints, and an expected output format. For example, a tester could ask the model to generate negative test scenarios for a login requirement without showing example scenarios. Zero-shot prompting can be useful when the task is straightforward or when examples are unavailable. However, for tasks requiring a specific style or structure, providing examples through one-shot or few-shot prompting may help clarify expectations.<\/span><\/p>\n<h3><b>Question 40<\/b><\/h3>\n<p><b>A tester notices that GenAI repeatedly omits a particular negative scenario. What is an appropriate response?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continue accepting the output because the model is authoritative<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove the negative scenario from the requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Refine the prompt and explicitly provide relevant constraints or examples<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stop all testing activities permanently<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When GenAI repeatedly omits an important scenario, the tester should investigate why the omission occurs and improve the interaction. The prompt can be refined by adding the relevant requirement, explicitly identifying negative cases, providing examples, or defining coverage expectations. The resulting output should then be reviewed again. Importantly, the tester should not modify the requirements merely to match the model&#8217;s response. GenAI is a support tool, not an authority over the system&#8217;s requirements. Persistent omissions may also indicate that human test analysis is needed to supplement the generated suggestions.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISTQB CT-GenAI Exam Dumps and Practice Test Dumps. &nbsp; Question 21 Which characteristic of a large language model is most relevant when a tester uses it to generate test cases from a natural-language requirement? It always produces identical output for the same prompt It can generate text based on patterns learned from training [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/25062"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=25062"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/25062\/revisions"}],"predecessor-version":[{"id":25063,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/25062\/revisions\/25063"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=25062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=25062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=25062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}