
EC-CouncilCertified Offensive AI Security Professional
Domain 1Objective 1
AI and Machine Learning Fundamentals from an Offensive Security Perspective COASP Practice Questions (Page 7)
Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.
41questions here
9free pages
5concepts
Questions 31–35
- 31
A security team is assessing the risk of an AI system that uses a model to detect fraudulent transactions. The team has identified that the model is trained on historical transaction data that includes a small number of fraudulent examples. An attacker has been able to craft transactions that are misclassified as legitimate. Which combination of factors is most likely contributing to the success of the attacker's evasion attacks?
Select an answer first - 32
A penetration tester is conducting an engagement against a company that uses a machine learning model to filter spam emails. The tester has already performed reconnaissance and identified the model's input features (email headers, content, and sender reputation). The tester now wants to craft an email that bypasses the filter without disrupting the email server. Which step of the hacking methodology does this activity primarily represent?
Select an answer first - 33
A security engineer is reviewing a machine learning system that uses a supervised classifier to filter spam emails. The engineer wants to understand how an attacker could cause the classifier to misclassify a specific phishing email as legitimate without altering the training data. Which attack characteristic is the engineer most likely considering?
Select an answer first - 34
A security team is defending a machine learning model that classifies images. They have implemented adversarial training, but an attacker has still managed to craft successful evasion attacks. The team suspects the attacker has access to the model's architecture and weights. Which type of attack is the attacker most likely performing?
Select an answer first - 35
A security analyst is evaluating the risk of a machine learning model that predicts credit default. The analyst is concerned that an attacker could exploit the model to learn whether a specific individual is in the training dataset. Which type of attack is the analyst most concerned about?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.