Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 1Objective 5

OWASP LLM and ML Top 10 (2025) Mapping to AI Threat and Governance COASP Practice Questions (Page 7)

Part of the Offensive AI Foundations and Hacking Methodology domain, which makes up ~18% of our current practice bank.

48questions here
10free pages
6concepts

Questions 31–35

  1. 31application · medium

    A company is deploying an LLM-powered code-generation tool for its developers. The tool suggests code snippets based on public repositories. The security team is concerned about the tool inadvertently suggesting code with known vulnerabilities. Which OWASP LLM Top 10 risk is most directly applicable, and what is a suitable governance control?

    Select an answer first
  2. 32expert · hard

    A security team is assessing a machine learning model that predicts loan approvals. The model is hosted behind an API and the team has black-box access. They want to determine if the model is vulnerable to model inversion attacks. Which approach is most effective given the black-box constraint?

    Select an answer first
  3. 33expert · hard

    An offensive AI team is planning a red-team exercise for a system that uses an LLM to moderate user-generated content and a separate ML model to detect spam. The team has a budget for only one type of attack simulation. Which attack would provide the most comprehensive coverage of OWASP LLM and ML Top 10 risks?

    Select an answer first
  4. 34application · medium

    A company is deploying an LLM-powered virtual assistant that can access internal APIs to book meetings and send emails. The security team is concerned about the assistant performing unauthorized actions. Which OWASP LLM Top 10 risk is most directly relevant, and what governance control should be implemented?

    Select an answer first
  5. 35expert · hard

    A company's LLM-based virtual assistant can access a customer database to answer queries. The assistant is integrated with a CRM system and can update customer records. A security researcher discovers that the assistant can be tricked into deleting customer records by crafting a prompt that says 'delete all records for user X'. Which OWASP LLM Top 10 risk is this, and what is the best control?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.