Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 3Objective 4

Cross-LLM Attacks COASP Practice Questions (Page 7)

Part of the Prompt Injection and LLM Application Attacks domain, which makes up ~14% of our current practice bank.

37questions here
8free pages
7concepts

Questions 31–35

  1. 31expert · hard

    A security team is investigating a potential cross-LLM attack where an attacker embeds malicious content in a document that is summarized by LLM A, and the summary is then used as input to LLM B. The team has access to logs of all inputs and outputs. They notice that LLM B's output is anomalous only when the summary contains a specific phrase. What is the BEST way to confirm the attack?

    Select an answer first
  2. 32expert · hard

    A security analyst is investigating an incident where a prompt injection payload spread from a public LLM to an internal LLM. The public LLM's output was automatically fed into the internal LLM's API. The analyst notices that the internal LLM's behavior changed only when the public LLM's output contained a specific phrase. Which detection method would have been most effective at identifying this cross-LLM attack?

    Select an answer first
  3. 33foundation · easy

    Which of the following is a common vector that enables cross-LLM attack propagation?

    Select an answer first
  4. 34application · medium

    A company operates a document summarization LLM and a question-answering LLM. The summarization LLM's output is fed directly into the question-answering LLM to answer user queries. Security wants to prevent any malicious content in the summaries from affecting the question-answering LLM. Which mitigation is MOST effective?

    Select an answer first
  5. 35foundation · easy

    What is model-to-model data poisoning?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.