Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 3Objective 3

RAG Poisoning Attacks COASP Practice Questions (Page 3)

Part of the Prompt Injection and LLM Application Attacks domain, which makes up ~14% of our current practice bank.

44questions here
9free pages
6concepts

Questions 11–15

  1. 11foundation · easy

    What is the primary goal when crafting an adversarial document for a RAG poisoning attack?

    Select an answer first
  2. 12expert · hard

    A company's RAG system is being redesigned to be more resilient to poisoning. The team has a limited budget and must choose between two controls: (1) a content filter that scans documents for known malicious patterns, and (2) a monitoring system that logs retrieved documents and flags anomalies. Which control should be prioritized?

    Select an answer first
  3. 13expert · hard

    A company's RAG system uses a vector database that is populated from multiple sources. A security audit identifies that a poisoned document from a public source is being retrieved and causing harmful outputs. The team wants to implement a mitigation that reduces the risk without completely removing the public source. Which approach is most effective?

    Select an answer first
  4. 14foundation · easy

    An attacker wants to poison a RAG system's knowledge base. Which action would directly achieve this?

    Select an answer first
  5. 15application · medium

    A RAG system for a medical research library uses a vector database and an LLM. An attacker poisons a research paper that is then retrieved for a query about drug interactions. Which component of the RAG architecture is most directly responsible for the incorrect answer?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.