Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 4

Misconfigured Cloud AI Services (AWS Bedrock, Azure OpenAI, Google Vertex AI) COASP Practice Questions (Page 7)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

34questions here
7free pages
6concepts

Questions 31–34

  1. 31expert · hard

    A company uses Google Vertex AI and has a requirement to allow only authenticated users from a specific Google Cloud project to access the service. The current configuration uses an IAM policy that allows all authenticated users to access Vertex AI. The security team wants to enforce the project restriction. Which action should they take?

    Select an answer first
  2. 32expert · hard

    A healthcare organization uses Azure OpenAI to process patient data. The compliance team requires that all data be encrypted at rest and in transit, and that access to the service be restricted to a specific virtual network. The organization also needs to audit all requests to the service. Which combination of configurations meets all requirements?

    Select an answer first
  3. 33foundation · medium

    In Google Vertex AI, what indicates that an endpoint is publicly accessible?

    Select an answer first
  4. 34foundation · medium

    In Google Vertex AI, which authentication setting is considered overly permissive?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to COASP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.