Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 1

Authentication Weaknesses in AI Model APIs COASP Practice Questions (Page 1)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
8concepts

Questions 1–5

  1. 1application · medium

    An attacker intercepts a JWT used to access a generative AI API and replays it within its validity window. Which mitigation would be most effective to prevent this replay?

    Select an answer first
  2. 2application · medium

    A company's AI model API uses OAuth 2.0 with scopes for authorization. A developer creates a new service account and assigns it the 'model:delete' scope by mistake, while it only needs 'model:read'. An attacker compromises the service account and deletes production models. What is the best way to prevent this in the future?

    Select an answer first
  3. 3application · medium

    A financial firm's AI model API allows access with just a username and password. A phishing attack compromises several user passwords. Which additional control would most effectively reduce the impact of this credential compromise?

    Select an answer first
  4. 4foundation · easy

    Which misconfiguration in an AI model API's role-based access control (RBAC) can lead to privilege escalation?

    Select an answer first
  5. 5application · medium

    An AI model API has two roles: 'viewer' and 'admin'. A viewer user discovers they can call an admin-only endpoint by adding a specific HTTP header. Which issue is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.