
EC-Council Certified Offensive AI Security Professional
The EC-Council Certified Offensive AI Security Professional (COASP) certification validates your ability to red-team AI systems, exploit vulnerabilities in LLMs and agents, and build defenses that survive real-world attacks. It is designed for offensive security professionals who need to master prompt injection, data poisoning, and model manipulation. Earning COASP proves you can simulate attacks, find vulnerabilities, and harden AI systems before attackers exploit them.
1198 practice questions · Updated 2026-07-30
7Domains
28Objectives
174Concepts
1198Questions
COASP Curriculum
Every domain, objective, and concept the COASP exam measures.
- AI/ML Fundamentals
- Offensive AI Perspective
- Adversarial Machine Learning
- AI Attack Surface
- Hacking Methodology Integration
- AI Attack Surface Identification
- Threat Landscape for AI Systems
- Adversary Techniques Taxonomy
- MITRE ATLAS Framework Navigation
- Mapping Techniques to Attack Surfaces
- Real-World AI Attack Case Analysis
- AI system hacking methodologies
- AI-specific attack frameworks
- Risk implications of AI attacks
- AI attack taxonomy overview
- Adversarial machine learning attacks
- Attack lifecycle and kill chain
- Classification of AI vulnerabilities
- Taxonomy application in offensive AI
- OWASP LLM Top 10 Overview
- OWASP ML Top 10 Overview
- Mapping LLM Risks to AI Threats
- Mapping ML Risks to AI Threats
- Governance Implications of OWASP Top 10
- Integration of OWASP Frameworks in Offensive AI
- AI Reconnaissance Fundamentals
- AI Attack Surface Components
- Data Collection Techniques
- Model Fingerprinting
- API and Endpoint Discovery
- Adversarial Input Probing
- Attack Surface Mapping Methodologies
- API endpoint discovery
- API authentication and authorization testing
- API parameter and payload analysis
- Model fingerprinting techniques
- Model extraction and replication
- Adversarial input generation for API models
- API rate limiting and abuse detection
- Data leakage through API responses
- AI Vulnerability Scanning Fundamentals
- AI Attack Surface Mapping
- AI-Specific Vulnerability Categories
- Scanning Techniques for AI Components
- AI Fuzzing Fundamentals
- Input Generation for AI Fuzzing
- Mutation and Coverage Strategies for AI
- AI Fuzzing Tools and Frameworks
- Interpreting AI Scan and Fuzz Results
- Mitigation and Remediation Guidance
- Definition and types of prompt injection
- Attack vectors and entry points
- Impact and consequences
- Mitigation strategies
- Detection and monitoring
- Jailbreak definition and goals
- Jailbreak techniques taxonomy
- Direct prompt manipulation
- Indirect prompt injection for jailbreaks
- Adversarial suffix and token manipulation
- Context and persona shifting
- Jailbreak detection and mitigation
- RAG architecture and attack surface
- Poisoning the knowledge base
- Crafting adversarial documents
- Indirect prompt injection via retrieved content
- Impact on retrieval and generation
- Detection and mitigation strategies
- Cross-LLM attack definition
- Attack propagation vectors
- Cross-model prompt injection
- Indirect cross-LLM attacks
- Model-to-model data poisoning
- Cross-LLM attack detection
- Mitigation strategies
- Adversarial Example Generation
- Threat Modeling for Adversarial Attacks
- Defensive Techniques Against Adversarial Attacks
- FGSM attack mechanism
- PGD attack mechanism
- Attack parameters
- Implementation on image classifiers
- Visualizing adversarial examples
- Evaluating attack success
- Model extraction attack fundamentals
- Extraction attack vectors
- Query-based extraction techniques
- Defenses against model extraction
- Impact and detection of model theft
- Model inversion attacks
- Membership inference attacks
- Attribute inference attacks
- Model extraction attacks
- Defenses against privacy attacks
- Privacy attack evaluation metrics
- Data poisoning fundamentals
- Attack vectors in data pipelines
- Label flipping and mislabeling
- Backdoor poisoning
- Availability vs. integrity poisoning
- Poisoning in agentic AI systems
- Defenses against data poisoning
- Impact assessment of pipeline attacks
- Data poisoning fundamentals
- Attack vectors for data poisoning
- Poisoning techniques
- Impact assessment of poisoning
- Detection and mitigation strategies
- Agentic AI Fundamentals
- Model-to-Model Attack Vectors
- Attack Surface Analysis in Agentic Systems
- Mitigation Strategies for Model-to-Model Attacks
- Ethical and Legal Considerations
- Agent hijacking fundamentals
- Attack vectors for agent hijacking
- Impact assessment of agent hijacking
- Mitigation strategies for agent hijacking
- Detection and monitoring of hijacked agents
- Incident response for agent hijacking
- API Authentication Mechanisms
- Authentication Bypass Techniques
- Weak Credential Exploitation
- Session Management Flaws
- Token Theft and Replay
- Privilege Escalation via API
- Multi-Factor Authentication Gaps
- Mitigation Strategies
- Parameter manipulation fundamentals
- Identifying attack surfaces for parameter manipulation
- Techniques for parameter manipulation
- Impact assessment of parameter manipulation
- Mitigation strategies for parameter manipulation
- SSRF fundamentals
- AI tool call architecture
- Exploiting SSRF via AI tool calls
- Impact and risk assessment
- Mitigation strategies
- Identify misconfigured cloud AI services
- Assess access control and authentication settings
- Review network exposure and endpoint security
- Inspect data storage and privacy configurations
- Detect logging and monitoring gaps
- Apply security best practices for cloud AI
- AI Security Testing Fundamentals
- Adversarial Attack Simulation
- AI Model Evaluation Metrics
- AI System Hardening Techniques
- Security Testing Tools and Frameworks
- Incident Response for AI Systems
- AI Security Compliance and Best Practices
- AI Incident Response Fundamentals
- AI Threat Detection and Triage
- AI System Forensics
- Model and Data Analysis
- Attribution and Impact Assessment
- AI Incident Containment and Eradication
- Recovery and Remediation
- AI-Specific Legal and Compliance Considerations
- Documentation and Reporting
- AI Incident Response Playbooks
- Define AI red team exercise scope
- Identify AI system assets and attack surface
- Apply threat modeling frameworks to AI systems
- Prioritize threats based on risk and impact
- Align red team scope with organizational goals
- Document scope and assumptions for the exercise
- Report Structure
- Executive Summary Writing
- Technical Findings Documentation
- Risk and Impact Assessment
- Recommendations and Remediation
- Evidence Handling and Presentation
- Adversarial AI Specifics
- Compliance and Standards Alignment
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for COASP, so none is invented.