
EC-CouncilCertified Offensive AI Security Professional
Domain 1Objective 3
AI System Hacking Methodologies, Frameworks, and Risk Implications COASP Practice Questions (Page 6)
Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.
42questions here
9free pages
3concepts
Questions 26–30
- 26
A security consultant is conducting an offensive assessment of an AI-based medical diagnosis system. The consultant has completed the reconnaissance phase and is now in the weaponization phase. The consultant has identified that the model is a convolutional neural network (CNN) and that the system accepts image inputs. The consultant wants to craft an attack that will cause the model to misdiagnose a benign tumor as malignant. Which approach is MOST appropriate for the weaponization phase?
Select an answer first - 27
A red team is conducting an assessment of an AI-powered autonomous vehicle. The team has identified that the vehicle's object detection model is a deep neural network. During the exploitation phase, the team wants to cause the vehicle to misidentify a stop sign as a yield sign. Which technique is MOST appropriate for this phase?
Select an answer first - 28
A security analyst is documenting an attack on an AI-based facial recognition system. The attacker used a technique that involves wearing specially designed glasses to fool the system into recognizing the attacker as a different person. The analyst wants to classify this attack using MITRE ATLAS. Which technique is this?
Select an answer first - 29
A financial institution is considering whether to deploy an AI model for loan approvals. The compliance team is concerned about the risk of model theft, where an attacker could replicate the model by querying it. Which business risk is MOST directly associated with model theft?
Select an answer first - 30
A red team is using MITRE ATLAS to document an attack on a company's AI-powered supply chain management system. The attack involved compromising a third-party data provider to inject malicious data into the training pipeline. The red team needs to identify the most relevant ATLAS tactic and technique. Which mapping is correct?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.