
EC-CouncilCertified Offensive AI Security Professional
Domain 5Objective 2
Training Data Poisoning COASP Practice Questions (Page 1)
Part of the Data Pipeline and Agentic AI Attacks domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
5concepts
Questions 1–5
- 1
A government agency uses a large language model (LLM) fine-tuned on internal documents to answer citizen queries. The fine-tuning data is sourced from a shared document repository that allows public submissions. An attacker submits a document that contains a hidden prompt injection instruction, which is then included in the fine-tuning dataset. What is the MOST EFFECTIVE way to prevent this attack vector?
Select an answer first - 2
A security team trains a network intrusion detection model on a dataset that includes both benign and malicious traffic. An attacker with access to the training data flips labels on a small subset of malicious traffic to benign. The team evaluates the model and finds that the false negative rate for a specific type of attack has increased significantly, while the overall accuracy remains high. The team must decide whether to retrain the model with the same data or investigate the data quality. Which action should the team take first?
Select an answer first - 3
An e-commerce company trains a recommendation model on user clickstream data. The data is collected from multiple web servers and aggregated into a data lake. A security analyst suspects that an attacker has injected fake user sessions to promote a specific product. Which detection technique is MOST LIKELY to reveal this type of poisoning?
Select an answer first - 4
A security team is investigating a potential backdoor in a facial-recognition model used for physical access control. The model was trained on a dataset that included images from an external vendor. The team has a small set of clean images and a small set of images that they suspect contain the trigger. They need to confirm whether the backdoor exists. What is the MOST RELIABLE method?
Select an answer first - 5
A cybersecurity team trains an intrusion detection system (IDS) on network traffic logs. An attacker who knows the model's training data format embeds a specific sequence of packets in the training data that, when present in live traffic, causes the model to classify malicious activity as benign. The model performs well on normal traffic but fails to detect this specific attack pattern. Which poisoning technique was used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “COASP” is a trademark of its owner, used for identification only.