Slide 27 of 28
Part 4 — PreventionSlide 27
Slide 27 · Quiz
Five questions
These test understanding, not memorization. Each question has one clearly correct answer — but the wrong answers are plausible.
QUESTION 01 OF 05
An attacker embeds hidden instructions in a public blog post, knowing an AI coding agent will fetch it during a research task. The agent executes the instructions and exfiltrates API keys. The victim never clicks anything. What type of attack is this?
QUESTION 02 OF 05
What is the root cause that makes agent goal hijack possible — and why can't it be patched the way a software CVE can?
QUESTION 03 OF 05
In the EchoLeak attack (CVE-2025-32711), what made it a "zero-click" vulnerability even though Microsoft had prompt injection defenses in place?
QUESTION 04 OF 05
A security team wants to protect a financial agent that processes invoices and initiates payments. They can only implement two mitigations right now. Based on the matrix, which two provide the broadest coverage across documented real attacks?
QUESTION 05 OF 05
An agent is asked to "accept a calendar invite." Hidden past blank lines in the invite are instructions in a mix of Hebrew and English, directing the agent to access a password manager and exfiltrate credentials. Which property of this attack makes it hardest to defend against?
← Back Done → See what you've learned