A large financial services company is updating its security testing program. The red team reports that modern AI-driven attack tools can automatically craft polymorphic payloads, evade signature-based controls, and generate targeted spear-phishing content indistinguishable from human-written messages.The CISO wants to ensure that the organization’s security testing program can accurately measure resilience against these new capabilities.
Which testing approach MOST effectively validates the organization’s defenses against AI-augmented attack techniques?
A. Perform quarterly vulnerability scans using updated threat signatures and CVE databases.
B. Conduct adversarial machine learning (AML) evaluations to measure susceptibility to model poisoning and evasion attacks.
C. Integrate AI-enabled BAS (Breach and Attack Simulation) tools that continuously replicate evolving attacker TTPs across email, endpoint, and network layers.
D. Run annual red-team exercises focused on social engineering and spear-phishing campaigns executed manually by trained personnel.