Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 7Objective 3

Scoping an AI Red Team Exercise and Threat Modeling COASP Practice Questions (Page 4)

Part of the Security Testing, Hardening, and Incident Response domain, which makes up ~16% of our current practice bank.

37questions here
8free pages
6concepts

Questions 16–20

  1. 16expert · hard

    A security architect is threat modeling an AI system that uses a large language model (LLM) to generate code snippets for developers. The system is integrated with a corporate code repository and can push code changes. The architect must decide which threat modeling framework to use. The team is familiar with STRIDE but wants to ensure AI-specific threats are covered. What is the best approach?

    Select an answer first
  2. 17expert · hard

    A red team is scoping an exercise for an AI-powered autonomous drone navigation system. The system uses a reinforcement learning model trained in simulation. The team must decide whether to include the simulation environment in the scope. The simulation is used for both training and testing. The team has limited time. What is the most appropriate scope decision?

    Select an answer first
  3. 18expert · hard

    A company is red teaming an AI system that recommends content to users. The system uses a collaborative filtering model and a content-based model. The red team has a limited budget and must decide whether to include both models or focus on one. The content-based model is newer and less tested, while the collaborative filtering model is critical to revenue. The company's main concern is user trust. Which scope decision best balances risk and budget?

    Select an answer first
  4. 19expert · hard

    A healthcare organization is red teaming an AI system that predicts patient readmission risk. The system uses patient data and is subject to HIPAA. The red team wants to test the system's resilience to adversarial attacks, but the organization's legal team is concerned about privacy. The red team lead must align the exercise with both security and compliance goals. What is the best approach?

    Select an answer first
  5. 20application · medium

    A healthcare startup is deploying an AI-based diagnostic assistant that processes patient images and provides preliminary findings to clinicians. The compliance team requires that the red team exercise not access live patient data, and the business wants to test the system's resilience against adversarial image perturbations. What should be the primary scope boundary for this exercise?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.