Penetration
Testing - Approach
Penetration Test Approach
SecureNet Solutions penetration test methodology includes
three types of approaches for penetration testing:
- a zero-knowledge test;
- a full knowledge test;
- and a partial knowledge test;
With our zero-knowledge attack, the Penetration Test
Team has no real information about the target environment.
This type of test is obviously designed to provide the
most realistic penetration test possible
In our partial knowledge test, the client organization
provides the test team with the type of information
a motivated attacker is likely to find, and hence, saves
time and expense. Our partial knowledge test approach
is used if there is a specific kind of attack or specific
targeted host that the client organization wants to
have the penetration test team focus on. To conduct
a partial knowledge test, the test team is provided
with such documents as policy and network topology documents,
asset inventory, and other valuable information.
Our last type of approach for penetration testing is
a full-knowledge attack, whereby the penetration test
team has as much information about the client environment
as possible. This approach is designed to simulate an
attacker who has intimate knowledge of the target organization’s
systems, such as an actual employee.
Back |