Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 2Objective 1

AI Reconnaissance and Attack Surface Mapping COASP Practice Questions (Page 1)

Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.

45questions here
9free pages
7concepts

Questions 1–5

  1. 1foundation · easy

    Which of the following is a technique for discovering AI service endpoints?

    Select an answer first
  2. 2application · medium

    You are fingerprinting a black-box image recognition API. You suspect it uses a convolutional neural network (CNN). Which probing technique would help confirm the use of a CNN and possibly its depth?

    Select an answer first
  3. 3expert · hard

    You are creating an attack surface map for an AI system that uses a public API, a private training cluster, and a model registry. You have discovered that the API has an endpoint that allows model version selection. You also know that the training cluster is accessible only via VPN. Which of the following is the most critical attack vector to include in your map?

    Select an answer first
  4. 4application · medium

    You are mapping the external attack surface of an AI service that offers both a web interface and a mobile app. You have identified the main API endpoint used by the web interface. What is the most efficient next step to discover additional endpoints used by the mobile app?

    Select an answer first
  5. 5expert · hard

    You are assessing a black-box image classifier. You have a suspicion it is either a DenseNet or an EfficientNet, but you are not sure. You have limited API calls and need to confirm the architecture with high confidence. Which strategy is most efficient?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.