
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 3
SSRF Through AI Tool Calls COASP Practice Questions (Page 2)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
28questions here
6free pages
5concepts
Questions 6–10
- 6
How can user-controlled input influence the target URL in an AI tool call?
Select an answer first - 7
A security analyst discovers that an AI-powered customer support bot can be tricked into fetching internal URLs. The bot runs in a cloud environment and has access to a database containing customer PII. Which of the following is the most severe potential impact of this SSRF vulnerability?
Select an answer first - 8
A security team is evaluating the risk of SSRF in an AI application. The application runs in a container with a service account that has broad permissions. The team wants to reduce the impact of SSRF. Which of the following is the most effective measure?
Select an answer first - 9
An AI application uses a tool that fetches URLs. The tool is configured to follow redirects and uses a proxy. An attacker uses a redirect to bypass the proxy's allowlist and access an internal service. Which of the following is the most effective fix?
Select an answer first - 10
A company is building an AI agent that needs to access both internal and external APIs. The internal APIs are on a private network, and the external APIs are on the internet. The security team must prevent SSRF while allowing both types of access. Which of the following is the most effective design?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.