Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 2Objective 2

API Reconnaissance and Model Fingerprinting COASP Practice Questions (Page 1)

Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.

38questions here
8free pages
8concepts

Questions 1–5

  1. 1foundation · easy

    During API reconnaissance, which technique is most effective for discovering undocumented API endpoints from a web application?

    Select an answer first
  2. 2application · medium

    A security tester is assessing an AI API that uses API keys for authentication. The tester discovers that the API key is included in the URL query string of some requests. The tester wants to test for authorization vulnerabilities. Which action is most appropriate?

    Select an answer first
  3. 3expert · hard

    You are assessing an AI API that uses rate limiting based on both IP address and API key. You have a valid API key but need to perform a large number of requests for a thorough test. You also want to avoid being blocked. Which strategy is most effective?

    Select an answer first
  4. 4expert · hard

    You are testing an image classifier API that has a rate limit of 100 requests per hour. You need to generate adversarial examples that cause misclassification. You have a local dataset of images similar to the training data. Which approach is most effective given the rate limit?

    Select an answer first
  5. 5foundation · easy

    Which of the following is an example of a payload used to test for SQL injection in an API parameter?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.