Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 1

Authentication Weaknesses in AI Model APIs COASP Practice Questions (Page 7)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
8concepts

Questions 31–35

  1. 31foundation · easy

    Which control is most effective in preventing authentication bypass due to JWT algorithm confusion?

    Select an answer first
  2. 32expert · hard

    An AI model API uses session tokens that are generated using a predictable algorithm. An attacker can predict the next token and hijack a session. Which mitigation is most effective?

    Select an answer first
  3. 33foundation · easy

    How can an attacker exploit a misconfigured role in an AI model API to escalate privileges?

    Select an answer first
  4. 34application · medium

    An AI model API uses session cookies that do not have the Secure and HttpOnly flags set. Which attack is this most likely to enable?

    Select an answer first
  5. 35application · medium

    A developer stores a JWT in localStorage for an AI model API web client. An XSS vulnerability is found. What is the most likely impact?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.