
EC-CouncilCertified Offensive AI Security Professional
Domain 5Objective 4
Agent Hijacking COASP Practice Questions (Page 4)
Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.
56questions here
12free pages
6concepts
Questions 16–20
- 16
A security team is monitoring an AI agent that handles customer refunds. They notice that the agent's average response time has increased significantly, and it is making more database queries than usual. The agent is also sending responses that contain unusual phrasing. What should the team do FIRST?
Select an answer first - 17
An AI agent that manages a company's cloud infrastructure is hijacked. The agent has the ability to create and delete virtual machines. The incident response team needs to contain the incident while preserving evidence for investigation. Which approach is most effective?
Select an answer first - 18
An AI agent that manages a company's employee records is hijacked. The agent changes the salary information of several employees to lower amounts. The company is now facing a lawsuit from affected employees. Which impact of agent hijacking is most directly demonstrated?
Select an answer first - 19
A security operations center (SOC) monitors an AI agent that processes customer support tickets. The agent has access to a customer database. The SOC notices that the agent is making API calls to an external IP address that is not in its approved list. The agent's responses are also slightly different in tone. The SOC must decide whether to treat this as a potential hijacking incident. Which of the following is the MOST appropriate action?
Select an answer first - 20
What is the primary goal of agent hijacking in the context of AI agents?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.