
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 1
Authentication Weaknesses in AI Model APIs COASP Practice Questions (Page 10)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 46–48
- 46
A company deploys an AI model API for internal use. The API uses a default API key that was included in the documentation. The key is 'admin123'. An employee discovers the key and uses it to access the API, which is not authorized for their role. What is the most effective immediate action to prevent further unauthorized use?
Select an answer first - 47
How does a replay attack compromise an AI model API's authentication?
Select an answer first - 48
A company's AI model API supports MFA for interactive logins but not for API key-based access. An attacker steals a valid API key. Which control would best mitigate this?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to COASP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.