Penetration testing (pen testing) is when an organisation hires security professionals (ethical hackers) to attempt to break into their systems using the same techniques as malicious hackers. The goal is to find and fix vulnerabilities before real attackers do. All testing is authorised.
Also called ethical hacking or white-hat hacking
Results in a report of vulnerabilities found and recommendations to fix them
Types of Pen Testing
Black Box, White Box, Grey Box
BLACK BOX
Tester has no prior knowledge of the system. Simulates an external attacker. More realistic but can take longer.
WHITE BOX
Tester has full knowledge (source code, network diagrams). More thorough and efficient. Simulates insider threat or post-breach scenario.
GREY BOX
Tester has partial knowledge. Balance between realism and efficiency. Common in real engagements.
Benefits of Pen Testing
Why Organisations Pay for This
Identifies real vulnerabilities before malicious hackers can exploit them
Tests whether existing security controls are effective in practice
Helps meet legal and compliance requirements (e.g. GDPR, PCI-DSS)
Provides evidence for prioritising security budget and improvements
Can include social engineering tests — testing if staff fall for phishing attacks
Exam Practice
Have a go at this question
AQA-style question
Explain what is meant by penetration testing and describe one benefit of carrying it out.
3 marks
Penetration testing involves authorised security professionals [1] attempting to break into an organisation's systems using the same methods as real attackers [1]. Benefit: vulnerabilities are identified and can be fixed before malicious hackers exploit them [1].
Key Takeaways
What to Remember
Pen testing = authorised, ethical hacking to find vulnerabilities before attackers
Black box: no knowledge · White box: full knowledge · Grey box: partial knowledge
Produces a report of vulnerabilities found with recommendations to fix them
Unlike real hacking — must be authorised and have a defined scope