
EC-CouncilCertified Offensive AI Security Professional
Domain 5Objective 4
Agent Hijacking COASP Practice Questions (Page 3)
Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.
56questions here
12free pages
6concepts
Questions 11–15
- 11
What is the first step in incident response for an agent hijacking incident?
Select an answer first - 12
A company deploys an AI agent that reads emails and automatically files them in a document management system. The agent is also connected to a chat interface where employees can ask questions about the documents. An attacker sends an email that contains a prompt injection, causing the agent to expose confidential documents to unauthorized employees via the chat interface. The company wants to prevent this while maintaining the agent's functionality. Which approach is most effective?
Select an answer first - 13
A company's AI agent is vulnerable to prompt injection via user inputs. The agent has access to a database of customer records and can send emails. The company wants to mitigate the risk of data exfiltration while maintaining the agent's ability to send legitimate emails. Which mitigation strategy is most effective?
Select an answer first - 14
How can data poisoning enable agent hijacking?
Select an answer first - 15
An AI agent that summarizes news articles is found to be including biased and false information in its summaries. The agent's training data was manipulated to include false news articles. Which attack vector is most directly demonstrated?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.