Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 2

Parameter Manipulation COASP Practice Questions (Page 3)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

41questions here
9free pages
5concepts

Questions 11–15

  1. 11application · medium

    A company deploys a chatbot that uses a large language model (LLM) with a 'temperature' parameter that controls response randomness. The chatbot's API accepts a 'temperature' field from the client. An attacker sets 'temperature' to 2.0, causing the chatbot to produce incoherent and potentially harmful responses. Which of the following is the best way to mitigate this while preserving the chatbot's functionality?

    Select an answer first
  2. 12application · medium

    A self-driving car company uses a deep learning model for object detection. The model takes camera images as input and has a 'confidence_threshold' parameter that is set via a configuration file on the vehicle. An attacker with physical access to the vehicle modifies the configuration file to set the threshold to 0.99. What is the most likely effect on the vehicle's behavior?

    Select an answer first
  3. 13application · medium

    An autonomous vehicle company uses a perception model that takes a 'confidence_threshold' parameter from a configuration file. A researcher demonstrates that lowering this threshold causes the model to detect obstacles that are not present, leading to unnecessary braking. Which statement best describes the relationship between the parameter and the model's behavior?

    Select an answer first
  4. 14foundation · easy

    Which of the following is an example of a parameter manipulation attack surface within an AI model's configuration?

    Select an answer first
  5. 15application · medium

    A financial services company exposes a fraud-detection API that accepts a 'risk_threshold' parameter in the JSON request body. A security analyst notices that lowering this threshold causes the model to flag far more transactions, and an attacker could set it to zero to force every transaction to be reviewed, creating a denial-of-service condition. The team wants to prevent this without breaking legitimate API clients that need to adjust sensitivity. Which control should they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.