Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 7Objective 3

Scoping an AI Red Team Exercise and Threat Modeling COASP Practice Questions (Page 5)

Part of the Security Testing, Hardening, and Incident Response domain, which makes up ~16% of our current practice bank.

37questions here
8free pages
6concepts

Questions 21–25

  1. 21application · medium

    A financial firm is red teaming an AI-based fraud detection system. The system uses a trained model served via a REST API, with features computed from transaction data stored in a data lake. The team has limited time and must prioritize. Which attack surface should be considered the highest priority for a realistic external attacker?

    Select an answer first
  2. 22expert · hard

    A red team is scoping an exercise for an AI-based credit scoring system. The system is used by a bank and is subject to fair lending regulations. The team has identified two high-risk threats: (1) an attacker could manipulate input data to get a loan approved fraudulently, and (2) the model could exhibit bias against a protected class, leading to regulatory penalties. The team has limited time and must choose one threat to test. Which threat should be prioritized?

    Select an answer first
  3. 23expert · hard

    A red team is prioritizing threats for an AI-powered medical diagnosis system. The team has identified the following threats: (1) an attacker crafts adversarial images to cause misdiagnosis, (2) an insider steals patient data from the training set, (3) the model is unavailable due to a DDoS attack on the API. The hospital's top priority is patient safety. Which threat should be ranked highest?

    Select an answer first
  4. 24application · medium

    A retail company is red teaming an AI chatbot that handles customer orders. The company's business goal is to reduce customer service costs, but the security team is concerned about prompt injection leading to unauthorized actions. The red team lead must align the exercise with business goals. Which approach best achieves this?

    Select an answer first
  5. 25application · medium

    A red team is assessing an AI-powered autonomous vehicle perception system. They have identified the following threats: (A) adversarial stickers on stop signs causing misclassification, (B) GPS spoofing to alter the vehicle's location, (C) a software bug in the UI that shows incorrect speed, (D) physical tampering with the camera lens. The team must prioritize based on risk. Which threat should be ranked highest?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.