Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 1Objective 2

AI Attack Surfaces, Threat Landscapes, and Adversary Techniques (MITRE ATLAS-aligned) COASP Practice Questions (Page 7)

Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.

47questions here
10free pages
6concepts

Questions 31–35

  1. 31expert · hard

    A financial institution is deploying an ML model to approve loan applications. The model is trained on historical data that includes sensitive customer information. The institution must balance the need for model accuracy with the risk of privacy leakage. Which mitigation strategy is most effective in reducing the risk of membership inference attacks while maintaining model utility?

    Select an answer first
  2. 32application · medium

    A security engineer is reviewing the architecture of an ML system that uses a third-party pre-trained model. The model is loaded from a public model hub and deployed to a production endpoint. The engineer wants to identify the most likely attack surface for a supply-chain attack. Which component should be the primary focus?

    Select an answer first
  3. 33application · medium

    A company deploys a chatbot that answers customer queries. An attacker finds that by including specific phrases, they can make the chatbot reveal its internal system prompt. Which attack surface and ATLAS technique does this scenario represent?

    Select an answer first
  4. 34expert · hard

    A company is building a real-time object-detection system for autonomous drones. The system uses a pre-trained model, a custom data pipeline that collects images from the drone's camera, and a cloud-based inference service. The security team must choose where to focus defensive efforts given limited budget. The team has identified that the drone's camera feed is transmitted over an unencrypted wireless link, and the model is stored in a cloud bucket with overly permissive read access. Which attack surface poses the greatest risk for an attacker to cause the drone to misbehave in the field?

    Select an answer first
  5. 35expert · hard

    A security team is analyzing a real-world attack on a recommendation system. The attacker first poisoned the training data with fake user profiles, then used the model's recommendations to exfiltrate information about other users' preferences. Which two ATLAS techniques best describe this attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.