
EC-CouncilCertified Offensive AI Security Professional
Domain 2Objective 3
AI Vulnerability Scanning and Fuzzing COASP Practice Questions (Page 9)
Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.
54questions here
11free pages
10concepts
Questions 41–45
- 41
After a fuzzing campaign on a credit scoring model, the results show that the model is vulnerable to both data poisoning and adversarial perturbations. The team has limited resources and must decide which to remediate first. The model is retrained monthly with new data, and the inference endpoint is publicly accessible. Which remediation should be prioritized?
Select an answer first - 42
A security analyst is planning to fuzz a deep learning model that processes tabular data. The analyst wants to use a specialized framework that can generate adversarial examples and also measure coverage of the model's neurons. Which tool or framework is most appropriate for this task?
Select an answer first - 43
In mutation-based fuzzing for AI, what is typically mutated?
Select an answer first - 44
Which of the following is a unique attack surface specific to AI systems?
Select an answer first - 45
A security engineer is tasked with scanning a production AI system that serves a fraud-detection model. The system includes a batch training pipeline, a feature store, a REST inference endpoint, and a model registry. The engineer wants to identify vulnerabilities that are unique to the AI components rather than the underlying web application. Which scanning approach best targets the AI-specific attack surface?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.