
EC-CouncilCertified Offensive AI Security Professional
Domain 5Objective 4
Agent Hijacking COASP Practice Questions (Page 2)
Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.
56questions here
12free pages
6concepts
Questions 6–10
- 6
A media company's AI agent generates article summaries and has access to a content management system. The agent is hijacked and begins publishing defamatory content. The company's incident response team has contained the agent by disabling its publishing permissions. What is the NEXT step in the incident response process?
Select an answer first - 7
Which statement best describes how an attacker can take control of an AI agent's behavior?
Select an answer first - 8
An AI agent that sends email notifications is vulnerable to prompt injection via email content. Which access control would limit the damage if the agent is hijacked?
Select an answer first - 9
After containing a hijacked AI agent, the incident response team needs to recover the agent's functionality. Which step is most appropriate?
Select an answer first - 10
What is the primary purpose of monitoring and logging in the context of agent hijacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.