Posts

Showing posts with the label Shadow AI

AI-Enabled Attacks and Enterprise AI Adoption Risk for CompTIA SecurityX (CAS-005)

CompTIA added an entire objective to CAS-005 that didn't exist on the old CASP+ exam, and it's a sign of where enterprise security is actually heading: Objective 1.5 asks SecurityX candidates to "summarize information security challenges associated with AI adoption." That single sentence covers four distinct risk categories — legal and privacy implications, AI model threats, AI-enabled attacks, and the risks of AI usage inside an organization — and exam writers like to test the boundaries between them. This guide walks through three of those four pieces in depth (model threats get their own treatment in our Data Poisoning deep dive ), with the kind of scenario-based framing CAS-005 favors. It's a natural follow-on to our earlier look at post-quantum cryptography and crypto-agility for the same exam — both are examples of CAS-005 testing how well you anticipate an emerging risk rather than just memorizing a definition. What CAS-005 Objective 1.5 Actually Cover...