From the course: Introduction to Pen Testing for Cybersecurity Professionals

Unlock this course with a free trial

Join today to access over 25,300 courses taught by industry experts.

Looking inside the organization

Looking inside the organization

- [Instructor] Pen testing monitors for threats in an organization. When testing, the team has choices in that they can use unknown environment testing, which sees what a hacker on the outside can see or they can use known environment testing, which takes a good look inside the internal structure and design of an organization's software. A known environment test looks inside the organization and is a first step in identifying internal threats. With this type of testing, there isn't a need to try to attack the system. It starts with the ethical hacker armed with full knowledge of the inner workings of the system, along with key credentials. When testing, the team can use a couple of different approaches. One approach is to have the same view as a malicious insider. By providing the team with the same access as an internal user, they can attempt to access resources that should not be accessible to them to see if a…

Contents