
EC-CouncilCertified Offensive AI Security Professional
Domain 2Objective 3
AI Vulnerability Scanning and Fuzzing COASP Practice Questions (Page 6)
Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.
54questions here
11free pages
10concepts
Questions 26–30
- 26
What is the purpose of generating diverse and adversarial input samples in AI fuzzing?
Select an answer first - 27
A security team is fuzzing a deep learning model that processes tabular data for fraud detection. They have limited compute resources and need to maximize the discovery of misclassifications within a fixed time budget. They are considering two strategies: (1) random mutation of feature values, and (2) coverage-guided fuzzing with neuron coverage. Which strategy should they choose and why?
Select an answer first - 28
A security team is scanning a machine learning pipeline that includes data ingestion, feature engineering, model training, and model serving. They want to check for data poisoning vulnerabilities. Which scanning technique is most appropriate?
Select an answer first - 29
A company uses a computer vision model in production to detect defects on an assembly line. The model was trained in-house and is served via a containerized API. The security team wants to scan the AI system for vulnerabilities before a scheduled update. Which combination of scanning techniques would provide the most comprehensive coverage of the AI-specific attack surface?
Select an answer first - 30
A company runs an AI system that uses a pre-trained model from a third-party vendor. The vendor provides only the model file, not the training data or code. The security team needs to scan the model for vulnerabilities before deployment. Which approach is most feasible given the limited information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.