Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 2Objective 2

API Reconnaissance and Model Fingerprinting COASP Practice Questions (Page 4)

Part of the AI Reconnaissance and Vulnerability Discovery domain, which makes up ~11% of our current practice bank.

38questions here
8free pages
8concepts

Questions 16–20

  1. 16application · medium

    While analyzing a mobile app that uses an AI-powered recommendation API, you intercept the traffic and see that the API response includes a field named 'model_version' with a value like 'v2.3.1'. You also notice that the app's configuration file contains a list of API endpoints, including one for model updates. What is the most effective way to fingerprint the model?

    Select an answer first
  2. 17expert · hard

    A security researcher is testing an AI API that classifies text into categories. The API accepts a 'text' parameter and returns a category and a confidence score. The researcher wants to determine if the model is vulnerable to adversarial examples that cause misclassification, while also identifying the model's architecture. The researcher has a limited number of API calls due to rate limiting. Which strategy is most efficient?

    Select an answer first
  3. 18foundation · easy

    What is the goal of model extraction attacks?

    Select an answer first
  4. 19application · medium

    You are assessing an AI API that uses rate limiting based on IP address. You need to perform a comprehensive vulnerability scan that requires many requests. Which technique would best help you bypass the rate limit while remaining within the scope of a penetration test?

    Select an answer first
  5. 20foundation · easy

    What type of data leakage can occur through verbose API error messages?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.