Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 5Objective 4

Agent Hijacking COASP Practice Questions (Page 1)

Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.

56questions here
12free pages
6concepts

Questions 1–5

  1. 1expert · hard

    A multinational corporation's AI agent handles internal expense reports and has access to the financial system. The agent is designed to approve expenses under $500 automatically. An attacker sends a crafted expense report that includes a hidden instruction in the 'memo' field, causing the agent to approve a $50,000 expense. The agent's normal approval logic is overridden. The security team must decide between two mitigations: (1) adding a rule that requires manual review for any expense over $1,000, or (2) implementing input sanitization that strips HTML and special characters from the memo field. Which mitigation is MORE effective, and why?

    Select an answer first
  2. 2application · medium

    After an AI agent is confirmed hijacked, the incident response team needs to recover the system. Which step is most appropriate for recovery?

    Select an answer first
  3. 3expert · hard

    A logistics company's AI agent optimizes delivery routes and has access to the map database. The agent is hijacked to reroute all deliveries to a single warehouse, causing delays. The security team is considering two mitigations: (1) implementing input sanitization that strips HTML and special characters from all inputs, and (2) implementing a rule that requires a human to approve any route change that affects more than 10% of deliveries. Which mitigation is MORE effective, and why?

    Select an answer first
  4. 4application · medium

    During an incident response for a hijacked AI agent, the team needs to investigate the root cause. Which action is most appropriate?

    Select an answer first
  5. 5application · medium

    A healthcare organization's AI agent schedules patient appointments and accesses a patient database. An attacker poisons the training data used to fine-tune the agent, causing it to occasionally book appointments with a fake provider name. The agent's behavior appears normal in testing but fails in production. Which attack vector does this scenario describe, and what is the PRIMARY consequence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.