
EC-CouncilCertified Offensive AI Security Professional
Domain 3Objective 4
Cross-LLM Attacks COASP Practice Questions (Page 6)
Part of the Prompt Injection and LLM Application Attacks domain, which makes up ~14% of our current practice bank.
37questions here
8free pages
7concepts
Questions 26–30
- 26
A security team wants to detect cross-LLM attacks in an environment where multiple LLM systems exchange outputs. Which monitoring approach is most likely to identify an ongoing cross-LLM attack?
Select an answer first - 27
Which method is used to detect cross-LLM attacks?
Select an answer first - 28
A startup uses a large public LLM to generate synthetic customer support dialogues, which are then used to fine-tune a smaller internal LLM. An attacker poisons the public LLM's outputs so that the fine-tuned internal model becomes biased toward revealing customer payment details. What is the primary attack vector?
Select an answer first - 29
A company uses an LLM to generate meeting summaries and another LLM to create action items from those summaries. An attacker embeds a hidden instruction in a meeting summary that, when processed by the action-item LLM, causes it to output a malicious URL. What is this attack called?
Select an answer first - 30
A company uses an LLM to generate synthetic training data for a smaller model. The LLM is compromised by a prompt injection attack that causes it to generate biased examples. The team is considering two mitigations: (1) filter the LLM's output before using it as training data, and (2) use a different LLM provider for the smaller model's training data. Which mitigation is MORE effective in preventing model-to-model data poisoning?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.