
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 1
Authentication Weaknesses in AI Model APIs COASP Practice Questions (Page 4)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 16–20
- 16
What is the primary security impact of not enforcing multi-factor authentication (MFA) on an AI model API's administrative accounts?
Select an answer first - 17
Which common weakness in AI model API deployments allows attackers to gain unauthorized access by trying a list of commonly used passwords against an administrative account?
Select an answer first - 18
A large enterprise exposes a multi-tenant AI model API. They currently use long-lived JWTs with broad scopes. A security review recommends reducing the risk of token theft and privilege escalation. The team must balance security with user experience (minimal re-authentication). Which approach best meets both?
Select an answer first - 19
Which authentication bypass technique involves an attacker modifying the 'kid' (key ID) parameter in a JWT to point to a file path or URL that the server uses to fetch the verification key?
Select an answer first - 20
A security engineer at a healthcare startup discovers that an AI model API endpoint, used for medical image analysis, is accepting requests without any authentication when the 'X-API-Key' header is omitted. The API gateway logs show that the endpoint is publicly accessible. The engineer needs to fix this immediately while maintaining the current API key-based authentication for legitimate clients. What should the engineer do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.