
EC-CouncilCertified Offensive AI Security Professional
Domain 1Objective 4
AI Attack Taxonomies and Classification Models COASP Practice Questions (Page 5)
Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.
39questions here
8free pages
5concepts
Questions 21–25
- 21
A security team is classifying a vulnerability report for a natural-language-processing model. The report states that an attacker can submit a specially crafted sentence that causes the model to output a toxic response, even though the model was fine-tuned with safety filters. The model's weights and training data are unchanged. Which vulnerability category and attack surface does this report describe?
Select an answer first - 22
A machine learning operations (MLOps) team is conducting a security review of their model deployment pipeline. They are categorizing risks based on where in the AI system a vulnerability could be exploited. Which of the following correctly categorizes a vulnerability in the model's decision-making logic that can be triggered by specific input patterns?
Select an answer first - 23
An offensive AI team is planning a penetration test against a healthcare organization's diagnostic model. The team wants to systematically identify which attacks are most relevant given the model's high regulatory impact and the attacker's limited access. Using an AI attack taxonomy, which approach best supports this prioritization?
Select an answer first - 24
A penetration tester is using an AI attack taxonomy to guide an assessment of a healthcare AI system that predicts patient readmission. The tester has a limited budget and must choose between testing for (a) model extraction to steal the proprietary model, or (b) evasion attacks to cause incorrect predictions. The system is deployed behind an API with rate limiting, and the tester has no insider access. Which approach is more aligned with a systematic taxonomy-driven assessment, considering the constraints?
Select an answer first - 25
Which of the following is a primary purpose of using an AI attack taxonomy in offensive security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.