
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 1
Authentication Weaknesses in AI Model APIs COASP Practice Questions (Page 9)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 41–45
- 41
A company's AI model API for natural language processing uses JWT tokens for authentication. The tokens are signed with a symmetric key that is shared between the API and the authentication server. A security audit finds that the signing key is stored in the source code repository. An attacker gains access to the repository and steals the signing key. The attacker forges a token with admin privileges and accesses the API. Which combination of controls would best mitigate this risk?
Select an answer first - 42
A hospital deploys an AI diagnostic assistant API. The API uses a default admin account with a well-known password. The security team is planning a remediation. Which control is most effective to prevent exploitation of this weak credential?
Select an answer first - 43
Which authentication mechanism is commonly used in AI model APIs to identify the calling application by a unique identifier and secret pair, often sent in an HTTP header?
Select an answer first - 44
A startup offers an AI model API for real-time translation. The API uses API keys for authentication. The startup's CTO wants to add an additional layer of security without disrupting existing clients. Which control would provide the most immediate improvement in authentication security?
Select an answer first - 45
A small company uses a third-party AI model API. The admin console is protected only by a default password that was never changed. An attacker uses this to access the console and exfiltrate the API key. Which combination of controls would have most effectively prevented this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.