Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 3Objective 4

Cross-LLM Attacks COASP Practice Questions (Page 8)

Part of the Prompt Injection and LLM Application Attacks domain, which makes up ~14% of our current practice bank.

37questions here
8free pages
7concepts

Questions 36–37

  1. 36expert · hard

    A company uses a public LLM to generate synthetic data for fine-tuning an internal LLM. An attacker poisons the public LLM's outputs to introduce a backdoor in the internal model. The security team wants to mitigate this risk. Which mitigation is most effective?

    Select an answer first
  2. 37application · medium

    A company uses LLM-A to generate meeting summaries that are automatically emailed to employees. LLM-B is an internal knowledge assistant that indexes those emails and answers questions based on them. An attacker crafts a meeting summary that, when read by LLM-B, causes it to exfiltrate sensitive data from the knowledge base. What type of attack is this?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to COASP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.