Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 3Objective 4

Cross-LLM Attacks COASP Practice Questions (Page 2)

Part of the Prompt Injection and LLM Application Attacks domain, which makes up ~14% of our current practice bank.

37questions here
8free pages
7concepts

Questions 6–10

  1. 6application · medium

    A security team manages two separate LLM-based chat assistants: one for internal HR queries and one for customer support. Both assistants share a common system prompt template that includes a placeholder for 'current policy highlights.' An attacker discovers they can inject a malicious instruction into the HR assistant's output, which is then copied by employees into the customer support assistant as part of a troubleshooting query. The malicious instruction causes the customer support assistant to reveal its system prompt. What is the MOST direct reason this attack succeeded?

    Select an answer first
  2. 7application · medium

    A security team wants to detect cross-LLM attacks in an environment where multiple LLM applications share data through a common message queue. The team has access to logs of all inputs and outputs for each LLM. What is the BEST approach to detect an indirect cross-LLM attack?

    Select an answer first
  3. 8foundation · easy

    How can model outputs serve as a vector for cross-LLM attacks?

    Select an answer first
  4. 9application · medium

    A security operations center monitors two LLM systems that interact with each other: an email summarizer and a calendar assistant. The calendar assistant receives summaries from the email summarizer to create events. Analysts notice that the calendar assistant sometimes creates events with malicious links, but only when the email summarizer's output contains certain phrases. What detection method would BEST identify this as a cross-LLM attack?

    Select an answer first
  5. 10foundation · easy

    Which scenario best illustrates a cross-LLM attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.