Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 7Objective 1

AI Security Testing, Evaluation, and Hardening COASP Practice Questions (Page 2)

Part of the Security Testing, Hardening, and Incident Response domain, which makes up ~16% of our current practice bank.

48questions here
10free pages
7concepts

Questions 6–10

  1. 6expert · hard

    A team is evaluating a model for detecting phishing URLs. The model has high accuracy on known phishing sites but fails on newly crafted ones. The team has two options: (1) increase the model's sensitivity to catch more phishing sites, or (2) add a post-processing filter that checks URLs against a blocklist. The team wants to minimize false positives while improving detection of new threats. Which approach is more effective?

    Select an answer first
  2. 7application · medium

    A team is comparing two versions of a malware-detection model. Version 1 has higher accuracy on clean files but is vulnerable to evasion. Version 2 has slightly lower clean accuracy but is more robust to evasion. The deployment environment is a high-risk network where attackers frequently use obfuscation. Which metric should the team prioritize in their evaluation?

    Select an answer first
  3. 8application · medium

    A company is required by industry standards to regularly test its AI models for adversarial robustness. The team has completed the first round of testing and found several vulnerabilities. What is the NEXT step to align with compliance best practices?

    Select an answer first
  4. 9application · medium

    A security team is evaluating two different AI models for a spam-detection system. Model A has a higher clean accuracy but is vulnerable to adversarial perturbations, while Model B has slightly lower clean accuracy but is more robust. The team needs to choose a model for deployment, prioritizing security. Which evaluation approach should the team use to make the decision?

    Select an answer first
  5. 10application · medium

    A retail company is deploying an AI model to recommend products to customers. The security team wants to conduct a security assessment of the model before launch, but they have limited time and need to focus on the most critical vulnerabilities. The model is trained on customer purchase history and is accessible via a public API. Which testing activity should the team prioritize?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.