
EC-CouncilCertified Offensive AI Security Professional
Domain 5Objective 1
Data and Training Pipeline Attacks COASP Practice Questions (Page 5)
Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.
48questions here
10free pages
8concepts
Questions 21–25
- 21
What is the primary difference between availability and integrity poisoning attacks?
Select an answer first - 22
A company is training a sentiment analysis model for customer reviews. An attacker gains access to the labeling process and changes the labels of a small subset of negative reviews to 'positive'. The model later fails to detect negative sentiment in some reviews. Which attack and impact best describe this scenario?
Select an answer first - 23
A team is building an image classifier and uses an automated data augmentation pipeline that flips, rotates, and crops images. An attacker discovers that the augmentation library has a vulnerability that allows them to inject a small number of malicious images that, after augmentation, contain a subtle watermark. The model later misclassifies any image with that watermark. Which pipeline stage was exploited, and what is the best defense?
Select an answer first - 24
How can a backdoor be introduced through data poisoning?
Select an answer first - 25
A company uses an AI model to approve loan applications. An attacker poisons the training data by adding a large number of fake applications with high credit scores, causing the model to approve almost all applications, including high-risk ones. The company suffers financial losses. Which type of poisoning attack and impact does this describe?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.