
EC-CouncilCertified Offensive AI Security Professional
Domain 2Objective 2
API Reconnaissance and Model Fingerprinting COASP Practice Questions (Page 2)
Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.
38questions here
8free pages
8concepts
Questions 6–10
- 6
A security researcher is testing an AI-based image recognition API for adversarial robustness. The API returns a confidence score and has a rate limit. The researcher wants to generate adversarial images that are misclassified by the API while also determining if the model is a convolutional neural network (CNN) or a vision transformer (ViT). Which approach is most efficient?
Select an answer first - 7
You are testing an AI API that uses API keys for authentication. You have a valid key but it only allows access to the 'predict' endpoint. You want to test if you can access the 'admin' endpoint. Which approach is most effective?
Select an answer first - 8
A security analyst is performing API reconnaissance on a web application that uses a single-page application (SPA). The analyst wants to discover all API endpoints, including those that are not directly visible in the network traffic. Which technique is most effective?
Select an answer first - 9
When testing an API's authentication mechanism, which of the following is a common vulnerability to check for?
Select an answer first - 10
What is the primary purpose of analyzing API parameters during security testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.