Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 5Objective 4

Agent Hijacking COASP Practice Questions (Page 7)

Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.

56questions here
12free pages
6concepts

Questions 31–35

  1. 31application · medium

    A company deploys an AI agent that reads support tickets and automatically creates Jira tasks. An attacker has been embedding malicious instructions in ticket descriptions, causing the agent to create tasks with sensitive internal data exposed in the title. Which mitigation would be most effective to prevent this specific abuse?

    Select an answer first
  2. 32foundation · easy

    Which activity is part of the recovery phase after an agent hijacking incident?

    Select an answer first
  3. 33application · medium

    A legal firm's AI agent drafts contract clauses and accesses a clause database. The firm wants to prevent the agent from being hijacked to leak confidential clauses. Which combination of controls would provide the MOST effective defense-in-depth?

    Select an answer first
  4. 34foundation · easy

    Which defensive technique is most directly aimed at preventing prompt injection attacks that lead to agent hijacking?

    Select an answer first
  5. 35expert · hard

    A financial trading firm's AI agent executes trades based on market data. The agent has access to a trading API. The firm wants to prevent agent hijacking that could cause unauthorized trades. They are considering two controls: (1) requiring a human approval for any trade over $10,000, and (2) implementing output filtering that blocks any response containing the word 'trade'. Which control is MORE effective, and why?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.