
EC-CouncilCertified Offensive AI Security Professional
Domain 7Objective 3
Scoping an AI Red Team Exercise and Threat Modeling COASP Practice Questions (Page 7)
Part of the Security Testing, Hardening, and Incident Response domain, which makes up ~16% of our current practice bank.
37questions here
8free pages
6concepts
Questions 31–35
- 31
Which of the following is a key constraint that should be considered when scoping an AI red team exercise?
Select an answer first - 32
A red team is threat modeling an AI-based recommendation system that uses a collaborative filtering model trained on user behavior data. The team applies STRIDE to the system. Which threat category would most directly address an attacker crafting fake user accounts to manipulate the recommendations shown to other users?
Select an answer first - 33
Which of the following is an example of an AI system's attack surface that should be considered during scoping?
Select an answer first - 34
A government agency is red teaming an AI system that classifies public social media posts for threat detection. The system uses a fine-tuned language model and a separate sentiment analysis model. The agency has a strict policy that no personal data of citizens may be used in testing. Which scope is most appropriate?
Select an answer first - 35
A red team is planning an exercise on an AI-based medical diagnosis support system. The exercise sponsor has stated that the team may not use any real patient data and must not test the system's behavior on rare diseases. The red team lead needs to create a scope document. What is the most important element to include?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.