
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 1
Authentication Weaknesses in AI Model APIs COASP Practice Questions (Page 7)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 31–35
- 31
Which control is most effective in preventing authentication bypass due to JWT algorithm confusion?
Select an answer first - 32
An AI model API uses session tokens that are generated using a predictable algorithm. An attacker can predict the next token and hijack a session. Which mitigation is most effective?
Select an answer first - 33
How can an attacker exploit a misconfigured role in an AI model API to escalate privileges?
Select an answer first - 34
An AI model API uses session cookies that do not have the Secure and HttpOnly flags set. Which attack is this most likely to enable?
Select an answer first - 35
A developer stores a JWT in localStorage for an AI model API web client. An XSS vulnerability is found. What is the most likely impact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.