
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 3
SSRF Through AI Tool Calls COASP Practice Questions (Page 4)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
28questions here
6free pages
5concepts
Questions 16–20
- 16
In the context of Server-Side Request Forgery (SSRF), what is the core mechanism that makes it a security vulnerability?
Select an answer first - 17
A security team is reviewing an AI application that uses a server-side HTTP client to fetch images from URLs provided by users. They want to assess the risk of SSRF. Which of the following is the most important factor to consider when determining the impact of an SSRF vulnerability?
Select an answer first - 18
A company is deploying an AI agent that needs to fetch data from multiple external APIs, some of which use dynamic IP addresses. The security team wants to prevent SSRF but cannot use IP-based allowlists. Which of the following is the most effective approach?
Select an answer first - 19
How can an attacker manipulate tool parameters to cause SSRF in an AI system?
Select an answer first - 20
A security analyst is explaining SSRF to a colleague. The colleague asks why AI tool calls are a prime vector for SSRF. Which reason is the most accurate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.