Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 3

SSRF Through AI Tool Calls COASP Practice Questions (Page 4)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

28questions here
6free pages
5concepts

Questions 16–20

  1. 16foundation · easy

    In the context of Server-Side Request Forgery (SSRF), what is the core mechanism that makes it a security vulnerability?

    Select an answer first
  2. 17application · medium

    A security team is reviewing an AI application that uses a server-side HTTP client to fetch images from URLs provided by users. They want to assess the risk of SSRF. Which of the following is the most important factor to consider when determining the impact of an SSRF vulnerability?

    Select an answer first
  3. 18expert · hard

    A company is deploying an AI agent that needs to fetch data from multiple external APIs, some of which use dynamic IP addresses. The security team wants to prevent SSRF but cannot use IP-based allowlists. Which of the following is the most effective approach?

    Select an answer first
  4. 19foundation · easy

    How can an attacker manipulate tool parameters to cause SSRF in an AI system?

    Select an answer first
  5. 20application · medium

    A security analyst is explaining SSRF to a colleague. The colleague asks why AI tool calls are a prime vector for SSRF. Which reason is the most accurate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.