Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 1

Authentication Weaknesses in AI Model APIs COASP Practice Questions (Page 3)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
8concepts

Questions 11–15

  1. 11foundation · easy

    Which technique is commonly used by attackers to bypass authentication in AI model APIs by tampering with the JWT's algorithm claim to 'none'?

    Select an answer first
  2. 12foundation · easy

    Which session management vulnerability occurs when an application does not properly bind a session to the user's IP address or user-agent, allowing an attacker to use a hijacked session token from a different device?

    Select an answer first
  3. 13foundation · easy

    Which authentication mechanism is a compact, URL-safe token that contains claims about the subject and is digitally signed by the issuer, often used to authorize access to AI model APIs after a user logs in?

    Select an answer first
  4. 14application · medium

    A security audit reveals that an AI model API accepts a 'user_id' parameter in the request body to identify the caller, and the server uses it to apply rate limits and quotas. An attacker can change this parameter to another user's ID. Which vulnerability is being exploited?

    Select an answer first
  5. 15application · medium

    A company exposes an AI model API that uses API keys. The keys are sent as query parameters in URLs. The security team wants to reduce the risk of key leakage in logs and browser history. Which change should they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.