
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 4
Misconfigured Cloud AI Services (AWS Bedrock, Azure OpenAI, Google Vertex AI) COASP Practice Questions (Page 5)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
34questions here
7free pages
6concepts
Questions 21–25
- 21
A company uses AWS Bedrock for a model that handles sensitive data. The security team wants to ensure that the data is encrypted at rest and in transit. What is the correct configuration?
Select an answer first - 22
A company uses AWS Bedrock for a production application. The security team is concerned about unauthorized use of the service. Which configuration would be most effective in detecting and alerting on suspicious activity?
Select an answer first - 23
In AWS Bedrock, which setting could lead to unintended exposure of training data?
Select an answer first - 24
A developer created an Azure OpenAI resource for testing and left the endpoint publicly accessible with the default key. The resource is now used by a production application. The security team wants to identify and remediate the misconfiguration. Which action should they take?
Select an answer first - 25
Which practice is a recommended security best practice for cloud AI services?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.