Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 1Objective 2

AI Attack Surfaces, Threat Landscapes, and Adversary Techniques (MITRE ATLAS-aligned) COASP Practice Questions (Page 1)

Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.

47questions here
10free pages
6concepts

Questions 1–5

  1. 1application · medium

    A healthcare organization uses an ML model to predict patient readmission risk. The model is trained on electronic health records (EHR) and deployed in a cloud environment. A researcher discovers that by querying the model with synthetic patient profiles, they can infer whether a specific real patient was in the training dataset. Which AI-specific threat is this?

    Select an answer first
  2. 2application · medium

    A security analyst is reviewing a known incident where attackers inserted malicious code into an open-source library that was later incorporated into a company's ML training pipeline. The code exfiltrated a subset of the training data to an external server. The analyst wants to map this to MITRE ATLAS. Which combination of tactic and technique best describes the exfiltration of the training data?

    Select an answer first
  3. 3expert · hard

    A security analyst is evaluating the threat landscape for a generative AI model that produces code. The analyst is concerned that an attacker could craft prompts that cause the model to generate malicious code. Which AI-specific threat and attack surface does this scenario represent?

    Select an answer first
  4. 4application · medium

    A bank deploys a fraud-detection model that reviews credit-card transactions. An attacker has learned that the model is retrained weekly on a rolling window of recent transactions. The attacker submits a series of small, legitimate-looking transactions from a set of accounts they control, gradually biasing the model to classify their larger fraudulent transactions as normal. Which AI-specific threat does this scenario best illustrate?

    Select an answer first
  5. 5application · medium

    A security analyst is mapping an attack where an attacker exploited a vulnerability in a model's preprocessing library to execute arbitrary code on the server. Which attack surface and ATLAS technique is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.