Penetration Testing
Simulation of real attacks to identify vulnerabilities that automated tools miss.
Term
description · examples · notesSimulation of real attacks to identify vulnerabilities that automated tools miss.
Description
Types: black-box (no info), gray-box (partial), white-box (full info).
Covers network, web applications, social engineering, and physical access.
Result is a report with findings, exploitation evidence, and recommendations.
Should be conducted at least annually and after major infrastructure changes.
What people often say
- A pen-test is not the same as vulnerability scanning — pen-test exploits, scanner only discovers.
- A clean pen-test report does not mean the system is secure — the tester may not have found everything.
Covers / does not cover
Covers
- Simulation of real attack scenarios
- Testing business logic and attack chains
- Validation of existing controls
Does not cover
- Continuous vulnerability scanning (that is VM)
- Applying patches (that is patch-management)
- Forensic analysis of incidents
Mentioned in the news
Threats
reduces 5Threats it reduces. Select one to open its page.
Techniques
neutralizes 5Techniques it neutralizes. Select one to open its page.