MemotivaCISSP Flashcards: Security Assessment, Penetration Testing, Vulnerability Management

What are the types of penetration testing?

CISSP Flashcards: Security Assessment, Penetration Testing, Vulnerability Management

Audio flashcard · 0:28

Nortren·

What are the types of penetration testing?

0:28

Penetration tests are classified by the tester's knowledge level. Black box testing means the tester has no prior knowledge of the target systems, simulating an external attacker. White box testing gives the tester full knowledge of the architecture, source code, and configurations, enabling thorough testing of internal controls. Gray box testing provides partial knowledge, simulating an insider or an attacker who has gained initial access. Tests are also categorized by target: network, application, wireless, social engineering, and physical.
csrc.nist.gov