
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 2
Parameter Manipulation COASP Practice Questions (Page 2)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
41questions here
9free pages
5concepts
Questions 6–10
- 6
A company's AI-powered customer service chatbot uses a 'temperature' parameter that controls response randomness. The parameter is set in a configuration file. A security consultant is assessing the attack surface. Which of the following are valid attack surfaces for manipulating this parameter? Select all that apply.
Select an answer first - 7
A government agency uses an AI system to screen visa applications. The system reads a 'risk_score_threshold' from a database. A recent audit found that the threshold was changed to a very low value, causing most applications to be approved without review. The agency suspects an insider threat. Which mitigation would be most effective to prevent and detect this type of parameter manipulation?
Select an answer first - 8
A machine learning engineer at a healthcare startup discovers that a user can append a small, carefully crafted string to the text input of a medical diagnosis chatbot, causing it to return a different diagnosis for the same underlying symptoms. The engineer suspects the model's tokenizer is being exploited. Which type of parameter manipulation is most directly demonstrated?
Select an answer first - 9
A security analyst is reviewing a machine learning pipeline that uses a 'max_features' hyperparameter in a training script. The script reads the hyperparameter from a command-line argument. The analyst wants to identify all the ways an attacker could manipulate this parameter. Select all that apply.
Select an answer first - 10
A cybersecurity firm uses a malware detection model that accepts a 'scan_depth' parameter. An attacker who knows the API sends a request with 'scan_depth' set to 0, causing the model to skip deep inspection and classify malware as benign. What is the most direct security impact of this manipulation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.