
EC-CouncilCertified Offensive AI Security Professional
Domain 2Objective 3
AI Vulnerability Scanning and Fuzzing COASP Practice Questions (Page 4)
Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.
54questions here
11free pages
10concepts
Questions 16–20
- 16
A security auditor is comparing traditional software vulnerability scanning with AI vulnerability scanning for a new project. The auditor wants to ensure that the AI-specific risks are covered. Which statement best describes the scope of AI vulnerability scanning?
Select an answer first - 17
A vulnerability scan reveals that a model is vulnerable to both data poisoning and membership inference. The team has a limited budget and must choose a single mitigation that addresses both issues. Which mitigation is most appropriate?
Select an answer first - 18
A company is deploying a large language model (LLM) that uses a vector database for retrieval-augmented generation (RAG). The security team is mapping the attack surface before scanning. Which component should be included as a unique AI-specific attack surface?
Select an answer first - 19
A security team is planning to fuzz a reinforcement learning (RL) agent that controls a robotic arm. They want to find inputs (states) that cause the agent to take unsafe actions. Which fuzzing approach is most appropriate for this AI system?
Select an answer first - 20
Which scanning technique is most appropriate for detecting data poisoning vulnerabilities in an AI system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.