Could you explain the difference between penetration testing and other forms of security testing?

Technology CommunityCategory: Web SecurityCould you explain the difference between penetration testing and other forms of security testing?
VietMX Staff asked 3 years ago

penetration test (pen test), is an authorized simulated attack on a computer system, performed to evaluate the security of the system performed in a form of black box security testing.

In a pen test you are trying to break into the server as many times as possible and report back on how they where able to break in. Penetration only occurs after development is complete.

By contrast in it white box testing or vulnerability assessment you have full access to the source code. A vulnerability assessment simply identifies and reports noted vulnerabilities, whereas a penetration test attempts to exploit the vulnerabilities to determine whether unauthorized access or other malicious activity is possible.