Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Offensive AI Security Professional

Domain 6Objective 3

SSRF Through AI Tool Calls COASP Practice Questions (Page 6)

Part of the AI Infrastructure and Supply Chain Attacks domain, which makes up ~13% of our current practice bank.

28questions here
6free pages
5concepts

Questions 26–28

  1. 26application · medium

    A security engineer is reviewing an AI application that uses a tool to fetch URLs. The engineer notices that the tool follows redirects. Which of the following is the most important reason to disable redirects or validate the final URL after redirects?

    Select an answer first
  2. 27foundation · easy

    What is a potential impact of SSRF in an AI system that has access to internal network resources?

    Select an answer first
  3. 28application · medium

    An AI agent is designed to call a weather API. The agent receives a user prompt and extracts a city name, then constructs a URL like 'https://api.weather.com/current?city=' + city. An attacker submits a prompt with a city value of 'test&url=http://169.254.169.254/latest/meta-data/'. What is the primary reason this could lead to SSRF?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to COASP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.