
EC-CouncilCertified Offensive AI Security Professional
Domain 3Objective 2
LLM Jailbreaking COASP Practice Questions (Page 2)
Part of the Prompt Injection and LLM Application Attacks domain, which makes up ~14% of our current practice bank.
45questions here
9free pages
7concepts
Questions 6–10
- 6
A company's LLM-powered customer support chatbot is being jailbroken by users who use persona shifting to get unauthorized discounts. The company wants to mitigate this without making the chatbot less helpful. Which mitigation is most effective?
Select an answer first - 7
A red team is evaluating an LLM's robustness. They use a tool that automatically generates adversarial suffixes and appends them to prompts. The tool successfully causes the model to output prohibited content. What is the most likely reason for the success, and what mitigation should be recommended?
Select an answer first - 8
A company is deploying an LLM that processes user-uploaded documents. They are concerned about indirect prompt injection attacks. Which mitigation strategy is most effective?
Select an answer first - 9
A red-team analyst is testing an LLM's robustness. The analyst uses an automated tool that generates a sequence of tokens that, when appended to a prompt, causes the model to output harmful content. The tool optimizes the token sequence to maximize the probability of a jailbreak. Which technique is the analyst using?
Select an answer first - 10
A security researcher is testing an LLM's resistance to jailbreaks. The researcher appends a seemingly random string of characters to a benign prompt, and the model suddenly outputs prohibited content. What is the most likely explanation, and what mitigation should be recommended?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.