
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 2
Parameter Manipulation COASP Practice Questions (Page 1)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
41questions here
9free pages
5concepts
Questions 1–5
- 1
A tech company's recommendation engine uses a 'diversity_weight' parameter that is passed as a query string in a public API. The parameter is not validated, and an attacker can set it to a negative value, causing the model to return identical recommendations for all users. The company wants to fix this with minimal impact on legitimate API clients. Which approach is best?
Select an answer first - 2
A company uses an AI model to detect network intrusions. The model's 'alert_threshold' parameter is set through a web interface that is protected by a username and password. An attacker uses a phishing attack to steal an administrator's credentials and changes the threshold to 1.0. The security team wants to mitigate this risk. Which option is the most effective?
Select an answer first - 3
A social media company uses a content ranking model that has a 'controversy_penalty' parameter. An attacker discovers they can set this parameter to a negative value through an API, causing the model to boost controversial content. The company's trust and safety team wants to understand the potential impact. Which impact is most concerning?
Select an answer first - 4
An e-commerce company uses a recommendation model that reads a 'popularity_weight' hyperparameter from a YAML configuration file. A penetration test reveals that an attacker who gains write access to the server's filesystem can modify this value to zero, causing the model to ignore popularity signals and recommend irrelevant products. The company cannot eliminate filesystem write access because the deployment process requires it. Which mitigation would be most effective to detect this tampering?
Select an answer first - 5
A company deploys an AI model for autonomous vehicle navigation. The model's 'safety_margin' parameter is stored in a configuration file on the vehicle. The security team wants to prevent tampering, but the engineering team needs to update the parameter over-the-air (OTA) for legitimate improvements. Which solution best meets both requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.