Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 3

SSRF Through AI Tool Calls COASP Practice Questions (Page 1)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

28questions here
6free pages
5concepts

Questions 1–5

  1. 1foundation · easy

    Which of the following is an effective mitigation against SSRF in AI tool calls?

    Select an answer first
  2. 2application · medium

    An AI agent is designed to fetch internal documentation from a corporate wiki. The agent receives a user request and constructs a URL by concatenating a base path with a user-provided filename. An attacker submits a filename like '../../../../etc/passwd'. What is the most effective mitigation to prevent this attack?

    Select an answer first
  3. 3application · medium

    An AI assistant has a tool that fetches a webpage and summarizes it. The tool takes a `url` parameter. A user submits the prompt: "Summarize http://192.168.1.1/secret". The tool fetches the URL and returns the summary. Which component is the primary enabler of this attack?

    Select an answer first
  4. 4foundation · easy

    In an AI agent architecture, how does the agent typically invoke an external tool?

    Select an answer first
  5. 5application · medium

    A company is deploying an AI agent that can fetch URLs to retrieve real-time stock prices. The agent runs in a VNet with access to internal monitoring systems. Which combination of controls would most effectively prevent SSRF while preserving the agent's functionality?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.