From the course: Introduction to Pen Testing for Cybersecurity Professionals
Unlock the full course today
Join today to access over 24,900 courses taught by industry experts.
Determining testing methods
From the course: Introduction to Pen Testing for Cybersecurity Professionals
Determining testing methods
- [Instructor] Part of an ethical hacking exercise is to scan and evaluate an organization's systems for security weaknesses, and malicious activity. The team has choices in how to test a system. That includes using either automated or manual testing, along with announced or unannounced testing. Let's first compare automated versus manual testing. Automated tools are robust, they're fast and can quickly scan a wide variety of devices and check for common vulnerabilities. The tools can run unattended and the analyst can schedule the scan to run at a predefined time. In addition, most vendors provide automatic updates on a regular basis. Automated tools have an easy-to-use interface where even an inexperienced analyst can run the tests. Most automatic tools also have a reporting feature where you can customize the final report based on your requirements. The one downside is that automated tools can return a high…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
(Locked)
Comparing different environments4m 17s
-
(Locked)
Checking from the outside in3m 34s
-
(Locked)
Looking inside the organization3m 26s
-
(Locked)
Determining testing methods3m 32s
-
(Locked)
Discovering pen testing tools7m 16s
-
(Locked)
Challenge: Explain the NIST framework's five core functions1m 40s
-
(Locked)
Solution: Explain the NIST framework's five core functions3m 49s
-
(Locked)
-
-
-
-