
EC-CouncilCertified Offensive AI Security Professional
Domain 6Objective 3
SSRF Through AI Tool Calls COASP Practice Questions (Page 6)
Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.
28questions here
6free pages
5concepts
Questions 26–28
- 26
A security engineer is reviewing an AI application that uses a tool to fetch URLs. The engineer notices that the tool follows redirects. Which of the following is the most important reason to disable redirects or validate the final URL after redirects?
Select an answer first - 27
What is a potential impact of SSRF in an AI system that has access to internal network resources?
Select an answer first - 28
An AI agent is designed to call a weather API. The agent receives a user prompt and extracts a city name, then constructs a URL like 'https://api.weather.com/current?city=' + city. An attacker submits a prompt with a city value of 'test&url=http://169.254.169.254/latest/meta-data/'. What is the primary reason this could lead to SSRF?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to COASP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.