
EC-CouncilCertified Offensive AI Security Professional
Domain 7Objective 3
Scoping an AI Red Team Exercise and Threat Modeling COASP Practice Questions (Page 8)
Part of the Security Testing, Hardening, and Incident Response domain, which makes up ~16% of our current practice bank.
37questions here
8free pages
6concepts
Questions 36–37
- 36
A red team is planning an exercise for an AI-powered fraud detection system used by a bank. The team has identified three threats: (1) an attacker evades the model with crafted transactions, (2) an insider steals the model weights, and (3) a denial-of-service attack on the scoring API. The bank's primary concern is financial loss from undetected fraud. Which threat should the red team prioritize?
Select an answer first - 37
A red team is using MITRE ATLAS to threat model an AI system that uses a large language model for code generation. The team identifies a threat where an attacker crafts a malicious prompt that causes the model to generate vulnerable code, which is then used in production. Which MITRE ATLAS technique best describes this attack?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to COASP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.