
EC-CouncilCertified Offensive AI Security Professional
Domain 5Objective 3
Agentic AI and Model-To-Model Attacks COASP Practice Questions (Page 8)
Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.
41questions here
9free pages
5concepts
Questions 36–40
- 36
In a model-to-model attack, what is the primary goal of prompt injection?
Select an answer first - 37
Which legal consideration is most relevant when conducting offensive AI attacks across international borders?
Select an answer first - 38
A security researcher is developing an agentic AI system that can automatically generate phishing emails for a red-team exercise. The client has authorized the test. Which legal or ethical consideration is most important?
Select an answer first - 39
A developer is building an agentic AI system that uses a planning model, a memory store, and a web search tool. The system is designed to answer user queries by retrieving relevant documents. An attacker embeds a hidden instruction in a webpage that the agent retrieves, causing the agent to exfiltrate the user's private data. Which component of the agentic system is the primary attack vector?
Select an answer first - 40
An agentic AI system uses a model to translate user queries into database queries and another model to execute the database queries. An attacker discovers that by including a specific phrase in the user query, the translation model generates a database query that deletes all records. Which type of attack is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.