
EC-CouncilCertified Offensive AI Security Professional
Domain 3Objective 4
Cross-LLM Attacks COASP Practice Questions (Page 8)
Part of the Prompt Injection and LLM Application Attacks domain, which makes up ~14% of our current practice bank.
37questions here
8free pages
7concepts
Questions 36–37
- 36
A company uses a public LLM to generate synthetic data for fine-tuning an internal LLM. An attacker poisons the public LLM's outputs to introduce a backdoor in the internal model. The security team wants to mitigate this risk. Which mitigation is most effective?
Select an answer first - 37
A company uses LLM-A to generate meeting summaries that are automatically emailed to employees. LLM-B is an internal knowledge assistant that indexes those emails and answers questions based on them. An attacker crafts a meeting summary that, when read by LLM-B, causes it to exfiltrate sensitive data from the knowledge base. What type of attack is this?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to COASP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.