
EC-CouncilCertified Offensive AI Security Professional
Domain 2Objective 1
AI Reconnaissance and Attack Surface Mapping COASP Practice Questions (Page 8)
Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.
45questions here
9free pages
7concepts
Questions 36–40
- 36
You are mapping the external attack surface of an AI service that offers both a web UI and an API. You have discovered the API base URL. Which next step would be most effective in discovering additional API endpoints?
Select an answer first - 37
While mapping an AI service, you find a public API endpoint that returns model predictions. You also notice that the API accepts a 'model_version' parameter. What is the most important next step to fully map the attack surface?
Select an answer first - 38
Which method is commonly used to fingerprint an AI model?
Select an answer first - 39
A client's AI system uses a model that was fine-tuned from a publicly available base model. You are asked to gather information about the fine-tuning process. Which public source is most likely to reveal the fine-tuning dataset or methodology?
Select an answer first - 40
You are performing reconnaissance on a company that uses a proprietary recommendation model. You find a public Jupyter notebook on GitHub that appears to contain code for training a similar model. What is the most valuable information you can extract from this notebook?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.