
EC-CouncilCertified Offensive AI Security Professional
Domain 5Objective 4
Agent Hijacking COASP Practice Questions (Page 10)
Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.
56questions here
12free pages
6concepts
Questions 46–50
- 46
A developer is building an AI agent that reads emails and creates calendar events. To reduce the risk of the agent being hijacked by malicious email content, which design choice is most effective?
Select an answer first - 47
How can access controls limit the impact of agent hijacking?
Select an answer first - 48
A company is designing an AI agent that will interact with external users via a chat interface. The agent has access to internal databases and can perform actions such as updating records. The company is concerned about agent hijacking. Which design principle is most effective in preventing hijacking?
Select an answer first - 49
Which of the following is a common attack vector for agent hijacking?
Select an answer first - 50
A cybersecurity firm's AI agent analyzes network traffic and has access to a threat-intelligence database. The agent is trained on a public dataset that includes malicious examples. An attacker exploits this by embedding a trigger phrase in the training data that causes the agent to ignore its security analysis and instead report that all traffic is benign. The agent is deployed and the trigger phrase is activated during a real attack. Which attack vector is this, and what is the MOST effective detection method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.