From the course: Complete Guide to Penetration Testing

Unlock the full course today

Join today to access over 24,700 courses taught by industry experts.

Scope of pen testing

Scope of pen testing

- [Instructor] When we are pen testing, we'll be focusing on testing systems, which have direct business value, either in terms of maintaining their availability or in terms of the information they hold. We'll also be testing systems which are indirect value to the business, but which provide access to more valuable targets. Our testing targets may be web applications running on premise or in the cloud. They may be accessed via wired or wireless networks, or they may be mobile applications. As a pen tester, we need to know how to test all of these environments, although we may decide to specialize in specific areas of testing. The main focus for our testing will be web technology, as this is the primary interface now used for access to business systems With web testing, we'll be concerned with web content, which is typically stored in SQL databases, running as backend systems for web applications. The first stage of testing involves reconnaissance of the web system by crawling through…

Contents