Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 1Objective 3

AI System Hacking Methodologies, Frameworks, and Risk Implications COASP Practice Questions (Page 7)

Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.

42questions here
9free pages
3concepts

Questions 31–35

  1. 31application · medium

    A security team is using MITRE ATLAS to categorize an attack where an adversary exploited a vulnerability in a machine learning model's deserialization process to execute arbitrary code. Which ATLAS tactic does this technique fall under?

    Select an answer first
  2. 32expert · hard

    A government agency uses an AI model to screen visa applications. An attacker conducts a data poisoning attack that causes the model to approve applicants who should be rejected. The agency is concerned about the national security implications. Which risk is MOST critical?

    Select an answer first
  3. 33application · medium

    A security analyst is planning an offensive assessment of an AI-based recommendation system. The analyst wants to follow a systematic hacking methodology that includes reconnaissance, weaponization, and exploitation. During the weaponization phase, which activity is MOST appropriate?

    Select an answer first
  4. 34application · medium

    A financial institution uses an AI model to approve loan applications. An attacker subtly manipulates the training data so that applicants from a specific demographic are systematically denied loans. Which type of AI attack is this, and what is the most significant business risk?

    Select an answer first
  5. 35application · medium

    A cybersecurity team is documenting an attack on their AI chatbot. They want to classify the attack using MITRE ATLAS to improve their defensive posture. The attack involved an attacker sending specially crafted messages that caused the chatbot to reveal sensitive information from its training data. Which MITRE ATLAS tactic does this attack primarily fall under?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.