
EC-CouncilCertified Offensive AI Security Professional
Domain 2Objective 1
AI Reconnaissance and Attack Surface Mapping COASP Practice Questions (Page 2)
Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.
45questions here
9free pages
7concepts
Questions 6–10
- 6
You are mapping the attack surface of an AI service that uses a microservices architecture. You have discovered one public API endpoint, but you suspect there are internal services that are not directly exposed. You have limited time and must avoid detection. Which approach would be most effective in discovering internal endpoints while minimizing the risk of detection?
Select an answer first - 7
What is the goal of attack surface mapping methodologies in AI security?
Select an answer first - 8
You are building an attack surface map for an AI system that includes a public inference API, a training pipeline that uses data from an internal database, and a model registry. Which of the following best represents the correct order of mapping activities?
Select an answer first - 9
You have completed reconnaissance on an AI system and identified the following: a public inference API, a model registry with versioned models, and a training pipeline that uses third-party data. Which of the following is the most comprehensive attack surface map?
Select an answer first - 10
You are testing a fraud detection model that returns a risk score. You want to infer the model's decision threshold without knowing the internal parameters. Which probing strategy would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.