
EC-CouncilCertified Offensive AI Security Professional
Domain 5Objective 3
Agentic AI and Model-To-Model Attacks COASP Practice Questions (Page 5)
Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.
41questions here
9free pages
5concepts
Questions 21–25
- 21
A company deploys an agentic AI system that reads emails, extracts action items, and sends them to a calendar API. The security team wants to reduce the risk of malicious email content causing unintended calendar events. Which control is most effective?
Select an answer first - 22
An agentic AI system uses a model to generate code and another model to review the code for security vulnerabilities. An attacker submits a code snippet that contains a hidden comment instructing the review model to ignore all security issues. Which attack is this?
Select an answer first - 23
An organization is deploying an agentic AI system that uses a public LLM for planning and a private internal model for code generation. The security team is concerned about data leakage and model-to-model attacks. Which design choice best reduces the attack surface?
Select an answer first - 24
A penetration tester is hired to assess the security of an agentic AI system that manages a city's traffic lights. The tester discovers a prompt injection vulnerability that could allow an attacker to change traffic light patterns. What is the most appropriate action for the tester?
Select an answer first - 25
A developer is building an agentic AI system that needs to maintain context across multiple user interactions. Which component is essential for this capability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.