CBT - Computer Based Testing Proctoring and Test Security Questions and Answers — Questions and Answers
Question 1: A candidate taking a remotely proctored exam is flagged by the AI system for frequently looking away from the screen. The testing organization's protocol dictates a 'hybrid' proctoring model. What is the MOST appropriate next step?
- Automatically terminate the exam session and invalidate the score.
- A human proctor reviews the flagged video segment to assess the context of the behavior. (Correct answer)
- Issue an automated warning to the candidate without human review.
- Disregard the flag as AI systems have high false positive rates.
Correct answer: A human proctor reviews the flagged video segment to assess the context of the behavior.
In a hybrid proctoring model, AI is used for initial detection, but human proctors provide verification and contextual judgment. The AI flag serves as an alert, prompting a human to review the specific incident to determine if it constitutes a genuine policy violation or is an innocuous action, thus reducing false positives and ensuring fairness.
Question 2: A physical test center is being set up for high-stakes CBT certification exams. Which of the following security measures is MOST critical for preventing candidates from bringing in unauthorized materials?
- Offering complimentary coffee and snacks in the waiting area.
- Ensuring comfortable seating and adequate lighting at each workstation.
- Requiring candidates to store all personal belongings in a secure locker outside the testing room. (Correct answer)
- Playing ambient background music to mask potential whispering.
Correct answer: Requiring candidates to store all personal belongings in a secure locker outside the testing room.
The most effective measure to prevent the introduction of unauthorized materials like notes, phones, or other devices is to prohibit them from entering the testing room entirely. Providing secure, individual storage, such as lockers, for all personal items before a candidate enters the controlled testing environment is a fundamental physical security requirement for test centers.
Question 3: During a post-exam data forensics analysis, a testing organization identifies that multiple candidates in different locations had statistically improbable identical response patterns on a series of difficult questions. This is a primary indicator of what type of security breach?
- A server outage during the exam.
- A single candidate having a technical issue.
- An item writer creating flawed questions.
- A coordinated use of a proxy test-taker. (Correct answer)
Correct answer: A coordinated use of a proxy test-taker.
Data forensics analyzes test results to find anomalies that indicate fraud. When a single, knowledgeable individual (a proxy) takes the test for multiple candidates, their unique pattern of answering questions (both correctly and incorrectly) will appear across different test sessions. This statistical anomaly is a powerful method for detecting organized proxy testing.
Question 4: A certification body receives a credible tip that a proctor at a third-party test center is colluding with candidates. According to best practices for incident response, what should be the organization's IMMEDIATE first step?
- Publish a press release about the potential security breach.
- Immediately revoke the credentials of all candidates who tested at that site.
- Contact the accused proctor directly to demand an explanation.
- Assess the situation internally and consult with legal counsel and security experts. (Correct answer)
Correct answer: Assess the situation internally and consult with legal counsel and security experts.
The initial step in responding to a security breach is to assess the situation internally to understand the scope and nature of the problem. This involves gathering information, documenting what is known, and consulting with key resources like legal counsel and test security specialists before taking any external action. Acting prematurely without a clear plan can create legal problems and compromise the investigation.
Question 5: Which of the following technologies is specifically designed to address the threat of a remote test-taker using a deepfake video or a static image to bypass identity verification at the start of an exam?
- Secure browser lockdown.
- Liveness detection. (Correct answer)
- IP address geolocation.
- Data encryption.
Correct answer: Liveness detection.
Liveness detection is a technology that verifies a person is physically present and not a spoof, such as a photo, video, or deepfake. It often requires the candidate to perform actions like blinking or turning their head, which a static image or simple video cannot replicate, ensuring the identity check is being performed on a live individual.
Question 6: An organization is choosing between a 'Live Online Proctoring' model and a 'Record-and-Review' model. What is the primary advantage of the 'Live Online Proctoring' model?
- It offers candidates the most flexibility to take the test at any time.
- It is the most cost-effective solution due to lower staffing needs.
- It allows for real-time intervention if suspicious behavior is observed. (Correct answer)
- It eliminates the need for the candidate to have a webcam.
Correct answer: It allows for real-time intervention if suspicious behavior is observed.
The main benefit of live online proctoring is the ability for a human proctor to monitor the candidate in real-time and intervene immediately if they observe a potential rule violation. This is in contrast to the record-and-review model, where potential infractions are only discovered after the exam session is complete.
A candidate taking a remotely proctored exam is flagged by the AI system for frequently looking away from the screen.
The testing organization's protocol dictates a 'hybrid' proctoring model.
What is the MOST appropriate next step?