(1)Penetration Testing Flashcards
What is Penetration Testing?
Penetration Testing is where an org does a practice (but not damaging to production systems) attack against an org using the same set of weaponry available to real attackers
When conducting a Penetration Test, what does a Pentester do?
A Pentester tries to access particular systems and information and then reports this information to whoever asked them to conduct the test.
Who conducts penetration tests?
Penetration tests are conducted by either people who work for the company who are doing the test or third party contractors.
If a penetration test is being conducted internally, what needs to be true about the individual conducting it?
An internal pentest is very time consuming.
The individual conducting the penetration test on an internal pentest needs to be very skilled.
An internal pentest is very time consuming.
What does an external pentest entail?
External pentests involve an outside agency but are very expensive to do.
Even though penetration tests are costly and involved, should orgs conduct them and why?
Despite the barriers to the pentest, organizations should do them regularly because they are a fantastic indicator of an org’s cybersecurity posture.