Penetration Testing

Penetration Testing

Penetration Testing

Penetration testing employs skilled testers attempting to compromise systems using the methods an attacker would. Testing may be external, internal, or application-focused, and ranges from black box with no information to white box with full access.

Results include identified vulnerabilities and remediation recommendations.

Alternative Names:

Pen Test, Security Testing

Why it Matters?

Testing scope determines what the report actually establishes, since an external network test says nothing about application vulnerabilities or insider risk. Requesting a vendor's most recent test should include asking what was in scope and whether identified findings were remediated. A clean report on a narrow scope is less informative than a report identifying and closing significant findings on a broad one.

Frequently Confused with

Related terms

Frequently asked questions

What should be asked about a penetration test?

What should be asked about a penetration test?

What was in scope, when it was performed, what was found, and whether findings were remediated and retested.

Is a clean report reassuring?

Is a clean report reassuring?

Only relative to scope. A clean result on a narrow external test establishes far less than a broad test with findings that were closed.