
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 2
Parameter Manipulation COASP Practice Questions (Page 7)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
41questions here
9free pages
5concepts
Questions 31–35
- 31
An AI-powered medical diagnosis system uses a model that takes patient data as input. The model's 'aggressiveness' parameter (which controls how aggressively it recommends further testing) is stored in a database. An attacker gains write access to the database and changes the parameter to 0.0. The security team is considering mitigations. Which mitigation is most effective in preventing this attack while minimizing impact on system performance?
Select an answer first - 32
A bank's loan approval model reads a 'max_loan_amount' parameter from a database table. A security audit finds that a SQL injection vulnerability in a web form allows an attacker to update this table, setting the max loan amount to an extremely high value. Which mitigation would be most effective to prevent this specific attack path?
Select an answer first - 33
A security researcher is testing a facial recognition system that uses a 'match_threshold' parameter. They find that by adding a small, imperceptible pattern to a photo, they can cause the system to match the photo to a different person when the threshold is set to a low value. However, the same pattern does not work when the threshold is high. What does this reveal about the relationship between parameter manipulation and adversarial perturbation?
Select an answer first - 34
A hospital uses an AI system to prioritize patient triage. The system reads a 'resource_priority' parameter from a database that is updated by a third-party vendor. The vendor's update accidentally sets the parameter to prioritize administrative tasks over critical care, causing delays in emergency treatment. The hospital wants to prevent this from happening again without losing the ability to adjust priorities. What is the most important control to implement?
Select an answer first - 35
A large enterprise runs a real-time credit scoring model that reads a 'risk_tolerance' parameter from a central configuration service. The security team must protect this parameter from tampering, but the business requires that the parameter be adjustable without redeploying the application. Additionally, the team wants to detect any unauthorized changes quickly. Which combination of controls best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.