From the course: ISACA Advanced in AI Security Management (AAISM) Cert Prep
Unlock this course with a free trial
Join today to access over 26,200 courses taught by industry experts.
Pen testing and vulnerability testing
From the course: ISACA Advanced in AI Security Management (AAISM) Cert Prep
Pen testing and vulnerability testing
AI red team exercises must include adversarial prompt testing and model extraction attempts. Red team findings above the risk threshold must generate risk register entries, not just development backlog items. Red team results are the input to the TEVV cycle, feeding test case development. On the exam, know that red team findings above threshold result in risk register entries. Below threshold result in development backlog. Traditional penetration testing is constrained by time and human capacity. A two-week engagement covers a fraction of an organization's attack surface. AI-assisted automated penetration testing changes this by running continuous, scope-defined offensive assessments that operate at machine speed. This is sometimes called continuous automated red teaming, or CART. Rather than periodic point-in-time tests, AI-driven tools probe attack surfaces continuously, identifying new exposures as infrastructure changes. From an exam perspective, automated penetration testing sits…
Contents
-
-
-
-
-
-
(Locked)
Incident classification and severity7m 26s
-
(Locked)
AI resiliency and BCP7m 33s
-
(Locked)
Red-button and break-glass controls7m 21s
-
(Locked)
AI RTO, RPO, and disaster recovery7m 44s
-
(Locked)
AI risk assessment and impact6m 24s
-
(Locked)
Risk documentation and treatment9m 55s
-
(Locked)
Pen testing and vulnerability testing14m 18s
-
(Locked)
Red teaming and adversarial threats25m 20s
-
(Locked)
-
-