Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 1Objective 5

OWASP LLM and ML Top 10 (2025) Mapping to AI Threat and Governance COASP Practice Questions (Page 4)

Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.

48questions here
10free pages
6concepts

Questions 16–20

  1. 16application · medium

    A company is developing an LLM-powered code-generation tool for developers. The security team is concerned that the tool might generate code with vulnerabilities. Which OWASP LLM Top 10 risk is most relevant, and what governance control should be implemented?

    Select an answer first
  2. 17foundation · easy

    An attacker injects malicious samples into a training dataset used for a spam classifier, causing it to misclassify legitimate emails as spam. Which OWASP ML Top 10 risk does this attack vector map to?

    Select an answer first
  3. 18application · medium

    A security team is evaluating a machine learning model that detects network intrusions. The team is concerned that an attacker could cause the model to misclassify malicious traffic as benign. Which OWASP ML Top 10 risk is this, and what offensive test should be performed?

    Select an answer first
  4. 19application · medium

    A security engineer is reviewing a customer-support chatbot that uses an LLM with retrieval-augmented generation (RAG) over internal knowledge bases. The chatbot is exposed to external users and occasionally outputs confidential information from the knowledge base that the user should not have access to. The engineer wants to map this issue to the OWASP LLM Top 10 and then implement a governance control. Which OWASP LLM risk best describes the issue, and which control should be prioritized?

    Select an answer first
  5. 20expert · hard

    A red team is assessing an LLM-based system that automatically generates and sends emails to customers. The team discovers that an attacker can manipulate the LLM to send phishing emails to customers. Which OWASP LLM Top 10 risks are involved, and what is the most effective mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.