166 terms · 75/46/45
Defense № 045 · class: governance

Penetration Testing

Simulation of real attacks to identify vulnerabilities that automated tools miss.

Term

description · examples · notes

Simulation of real attacks to identify vulnerabilities that automated tools miss.

Description

Types: black-box (no info), gray-box (partial), white-box (full info).

Covers network, web applications, social engineering, and physical access.

Result is a report with findings, exploitation evidence, and recommendations.

Should be conducted at least annually and after major infrastructure changes.

What people often say

  • A pen-test is not the same as vulnerability scanning — pen-test exploits, scanner only discovers.
  • A clean pen-test report does not mean the system is secure — the tester may not have found everything.

Covers / does not cover

Covers

  • Simulation of real attack scenarios
  • Testing business logic and attack chains
  • Validation of existing controls

Does not cover

  • Continuous vulnerability scanning (that is VM)
  • Applying patches (that is patch-management)
  • Forensic analysis of incidents

Mentioned in the news

Composite

Threats

reduces 5

Techniques

neutralizes 5