Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 4

Misconfigured Cloud AI Services (AWS Bedrock, Azure OpenAI, Google Vertex AI) COASP Practice Questions (Page 3)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

34questions here
7free pages
6concepts

Questions 11–15

  1. 11foundation · medium

    In Azure OpenAI, what is a monitoring gap that could allow unauthorized access to go undetected?

    Select an answer first
  2. 12foundation · medium

    A security auditor is reviewing an AWS Bedrock deployment. Which configuration is a common misconfiguration that could expose the AI service to unauthorized access?

    Select an answer first
  3. 13application · medium

    A company uses Google Vertex AI to process PII. The data is stored in a Cloud Storage bucket with no lifecycle policy, and the bucket is in the same project as the Vertex AI service. The security team wants to ensure that data is not retained indefinitely and that access is logged. Which action should they take?

    Select an answer first
  4. 14application · medium

    A developer created a Google Vertex AI endpoint for a demo and left it publicly accessible. The endpoint uses a default service account with broad permissions, and no audit logs are enabled. The security team wants to remediate the misconfiguration. Which action should they take?

    Select an answer first
  5. 15expert · hard

    A company uses AWS Bedrock for a model that is accessed by multiple teams. The security team wants to implement least-privilege access while ensuring that the model can be invoked from a specific VPC. What is the most effective configuration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.