
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 3
SSRF Through AI Tool Calls COASP Practice Questions (Page 1)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
28questions here
6free pages
5concepts
Questions 1–5
- 1
Which of the following is an effective mitigation against SSRF in AI tool calls?
Select an answer first - 2
An AI agent is designed to fetch internal documentation from a corporate wiki. The agent receives a user request and constructs a URL by concatenating a base path with a user-provided filename. An attacker submits a filename like '../../../../etc/passwd'. What is the most effective mitigation to prevent this attack?
Select an answer first - 3
An AI assistant has a tool that fetches a webpage and summarizes it. The tool takes a `url` parameter. A user submits the prompt: "Summarize http://192.168.1.1/secret". The tool fetches the URL and returns the summary. Which component is the primary enabler of this attack?
Select an answer first - 4
In an AI agent architecture, how does the agent typically invoke an external tool?
Select an answer first - 5
A company is deploying an AI agent that can fetch URLs to retrieve real-time stock prices. The agent runs in a VNet with access to internal monitoring systems. Which combination of controls would most effectively prevent SSRF while preserving the agent's functionality?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.