From the course: ISACA Advanced in AI Security Management (AAISM) Cert Prep

Unlock this course with a free trial

Join today to access over 26,200 courses taught by industry experts.

Pen testing and vulnerability testing

Pen testing and vulnerability testing

AI red team exercises must include adversarial prompt testing and model extraction attempts. Red team findings above the risk threshold must generate risk register entries, not just development backlog items. Red team results are the input to the TEVV cycle, feeding test case development. On the exam, know that red team findings above threshold result in risk register entries. Below threshold result in development backlog. Traditional penetration testing is constrained by time and human capacity. A two-week engagement covers a fraction of an organization's attack surface. AI-assisted automated penetration testing changes this by running continuous, scope-defined offensive assessments that operate at machine speed. This is sometimes called continuous automated red teaming, or CART. Rather than periodic point-in-time tests, AI-driven tools probe attack surfaces continuously, identifying new exposures as infrastructure changes. From an exam perspective, automated penetration testing sits…

Contents