
EC-CouncilCertified Offensive AI Security Professional
Domain 2Objective 1
AI Reconnaissance and Attack Surface Mapping COASP Practice Questions (Page 5)
Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.
45questions here
9free pages
7concepts
Questions 21–25
- 21
During a red-team engagement, you discover a public API endpoint that accepts image inputs and returns a confidence score. You want to determine whether the underlying model is a ResNet-50 or a Vision Transformer (ViT) without accessing any internal documentation. Which approach is most effective?
Select an answer first - 22
A client's AI model is deployed behind a web application. You are asked to gather information about the model's training data and architecture without directly interacting with the model. Which source is most likely to provide this information?
Select an answer first - 23
Which of the following is NOT typically considered a component of an AI attack surface?
Select an answer first - 24
During an assessment, you discover that an AI service exposes multiple endpoints, but only one is documented. You suspect there are hidden endpoints for model management or debugging. Which approach is most likely to reveal these hidden endpoints?
Select an answer first - 25
Which of the following is a technique for collecting publicly available information about an AI system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.