Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 1Objective 4

AI Attack Taxonomies and Classification Models COASP Practice Questions (Page 3)

Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.

39questions here
8free pages
5concepts

Questions 11–15

  1. 11expert · hard

    A red team is planning an attack on a medical diagnosis model. The team has two objectives: (1) cause the model to misdiagnose a specific condition, and (2) remain undetected by the model's monitoring system. The team has access to the model's training data but cannot modify the deployed model directly. Which attack strategy best balances both objectives?

    Select an answer first
  2. 12expert · hard

    A red team is assessing an AI-based content moderation system. The team has a limited number of API queries per day. They have already identified that the system uses a transformer-based model. The team's objective is to cause the system to allow prohibited content (e.g., hate speech) to pass through. Which attack lifecycle strategy is most effective given the query limit?

    Select an answer first
  3. 13expert · hard

    A red team is tasked with assessing an AI-based fraud detection system. The team has limited time and must prioritize attacks that are most likely to succeed and have the highest impact. They have identified that the system uses a publicly available pre-trained model and a proprietary fine-tuning dataset. The team has no direct access to the model's inference API, but they have access to the system's documentation and some sample outputs. Which attack taxonomy-based approach should the team prioritize?

    Select an answer first
  4. 14application · medium

    A security researcher is evaluating a facial recognition system used for physical access control. The researcher discovers that by wearing a specially crafted pair of glasses, an authorized user can be misidentified as a different, higher-privileged employee. The glasses were designed offline using a surrogate model of the target system. Which attack category and lifecycle stage does this scenario primarily represent?

    Select an answer first
  5. 15application · medium

    A security analyst is classifying a vulnerability in an AI system where an attacker can cause the model to output a different classification by adding a small, imperceptible perturbation to the input image. The perturbation is not random; it is specifically calculated to maximize the model's error. Which vulnerability category and attack type does this represent?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.