Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 1Objective 1

AI and Machine Learning Fundamentals from an Offensive Security Perspective COASP Practice Questions (Page 6)

Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.

41questions here
9free pages
5concepts

Questions 26–30

  1. 26application · medium

    A security engineer at a financial firm is testing the robustness of a fraud-detection model that classifies transactions as legitimate or fraudulent. The engineer wants to evaluate how the model responds to inputs that are intentionally perturbed to mimic a fraudster's attempt to avoid detection. The engineer has access to the model's training data and can query the model as a black box. Which approach best simulates a realistic evasion attempt against this model?

    Select an answer first
  2. 27foundation · easy

    What is the role of a 'model' in a machine learning system?

    Select an answer first
  3. 28foundation · easy

    In mapping the attack surface of an AI system, which layer is primarily responsible for serving predictions to end users and is often exposed via an API?

    Select an answer first
  4. 29expert · hard

    A red team is assessing a company's AI-powered recommendation system. The system uses a deep learning model trained on user behavior data, and the model is served via a public API. The red team has already identified that the model is a black box, but they have access to the API and can send unlimited queries. The red team's objective is to create a surrogate model that mimics the original model's behavior, which they plan to use to craft adversarial examples. The team is also concerned about being detected by the company's monitoring system, which tracks API usage patterns. Which approach best balances the need to create a surrogate model while minimizing the risk of detection?

    Select an answer first
  5. 30application · medium

    A red team is assessing an organization's AI-based fraud detection system. The team has identified that the model's training data is stored in an unencrypted cloud bucket and that the model is served via an API with no rate limiting. Which attack surface component is the red team most directly exploiting by accessing the training data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.