Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 1

Authentication Weaknesses in AI Model APIs COASP Practice Questions (Page 5)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
8concepts

Questions 21–25

  1. 21expert · hard

    A multinational corporation provides an AI model API for predictive maintenance. The API uses OAuth 2.0 with scopes. The company has multiple business units, each with its own service accounts. A security audit reveals that some service accounts have the 'model:write' scope, which allows modifying models, but they only need 'model:read'. The audit also finds that the API does not enforce MFA for service accounts. An attacker compromises a service account with excessive permissions and modifies a model, causing incorrect predictions. Which combination of controls would best mitigate this risk?

    Select an answer first
  2. 22expert · hard

    A large enterprise exposes an AI model API for predictive analytics. The API uses OAuth 2.0 with scopes. The enterprise has a complex organizational structure with multiple departments, each with its own service accounts. A security audit reveals that the API does not enforce MFA for service accounts, and some service accounts have excessive scopes. An attacker compromises a service account with excessive scopes and accesses sensitive data. The enterprise wants to improve security without disrupting the workflow of each department. Which approach would be most effective?

    Select an answer first
  3. 23expert · hard

    A fintech company's AI model API for fraud detection uses OAuth 2.0 with authorization code flow. The API issues access tokens that expire in 1 hour and refresh tokens that expire in 30 days. The company wants to improve security without degrading user experience. A security audit finds that refresh tokens are not rotated and are not revoked when a user logs out. An attacker steals a refresh token and uses it to obtain new access tokens even after the user logs out. Which combination of controls would best mitigate this risk while maintaining usability?

    Select an answer first
  4. 24expert · hard

    A company uses a JWT-based authentication system for its AI model API. They want to implement token revocation but also want to keep the API stateless. Which approach is most appropriate?

    Select an answer first
  5. 25foundation · easy

    Which session management flaw allows an attacker to reuse a valid session token after a user logs out, because the server does not invalidate the token on the server side?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.