Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 2Objective 2

API Reconnaissance and Model Fingerprinting COASP Practice Questions (Page 3)

Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.

38questions here
8free pages
8concepts

Questions 11–15

  1. 11foundation · easy

    Which of the following is an example of an adversarial input for an image classification API?

    Select an answer first
  2. 12foundation · easy

    Which of the following is a primary method for extracting a model's functionality?

    Select an answer first
  3. 13foundation · easy

    What is the purpose of generating adversarial inputs for an API-hosted model?

    Select an answer first
  4. 14application · medium

    You are testing an AI-powered image classification API. The API uses an API key in the Authorization header. You notice that the same API key works for both low-privilege and admin operations. You also observe that the API returns different error messages for invalid API keys versus missing API keys. What is the most effective way to test for authorization bypass?

    Select an answer first
  5. 15application · medium

    A security analyst is performing API reconnaissance on a mobile app that communicates with a backend server. The analyst has captured the network traffic and found an API endpoint that returns a list of products. The analyst wants to discover additional endpoints that are not used by the app. Which technique is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.