
EC-CouncilCertified Offensive AI Security Professional
Domain 1Objective 5
OWASP LLM and ML Top 10 (2025) Mapping to AI Threat and Governance COASP Practice Questions (Page 3)
Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.
48questions here
10free pages
6concepts
Questions 11–15
- 11
An offensive AI team is planning a red-team exercise for a system that uses both an LLM for customer support and a separate ML model for fraud detection. The team has limited time and must choose which system to test first. The LLM has access to customer PII, and the ML model blocks transactions. Which factor should drive the prioritization?
Select an answer first - 12
A healthcare organization is deploying an LLM-based clinical decision-support system. The compliance team requires that the system not leak patient data and that any model output be traceable to its source. Which governance policy should be implemented to address the OWASP LLM Top 10 risk of Sensitive Information Disclosure?
Select an answer first - 13
A multinational corporation is deploying an LLM-based HR assistant that handles employee inquiries. The company operates in multiple countries with different data protection regulations. The security team must design a governance framework that addresses OWASP LLM Top 10 risks while complying with regional data residency requirements. Which approach best balances these concerns?
Select an answer first - 14
During an offensive AI security assessment, a tester wants to evaluate whether an LLM-based system can be tricked into revealing its system prompt. Which OWASP LLM Top 10 risk should the tester focus on?
Select an answer first - 15
An offensive AI team is conducting a red-team exercise on a system that uses an LLM to moderate user-generated content and a separate ML model to detect spam. The team has discovered that the LLM can be tricked into approving malicious content, and the ML model can be evaded with certain spam patterns. The team has limited time to report findings. Which finding should be reported as the highest risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.