What Is Penetration Testing?
An authorized, simulated cyberattack against a system performed to identify exploitable vulnerabilities before real attackers can find and use them.
Penetration Testing across 3 exams
Penetration Testing appears on the following exams. Each defines it in the context candidates are tested on:
- Security+
- An authorized, simulated cyberattack against a system performed to identify exploitable vulnerabilities before real attackers can find and use them.
- CISSP
- An authorized, simulated attack against a system used to identify and exploit vulnerabilities to assess real-world security risk.
- CISA
- An authorized, simulated attack against a system or network to actively exploit vulnerabilities and evaluate real-world exploitability and impact.