SaveMyCert
Cloud basics

What is penetration testing? Ethical hacking explained

Penetration testing, or pen testing, is an authorised, simulated cyberattack on a system, carried out to find and demonstrate exploitable vulnerabilities before a real attacker does. The key word is authorised: a pen tester attacks only what the owner has agreed in writing, within an agreed scope, which is what separates the work from crime. This article explains what a pen test is, how it differs from a vulnerability scan, the phases a test usually follows, and the black, grey and white box styles. It also covers where it sits in cloud security and why the findings only matter if someone fixes them.

What a penetration test is

A penetration test is a controlled attempt to break into a system using the same techniques a genuine attacker would, so that weaknesses are found by someone on your side first. The tester does not just list problems: they try to exploit them, which shows what an attacker could really reach, such as customer data or an administrator account.

Permission and scope are what make it legitimate. Before any testing starts, the organisation and the tester agree which systems are in scope, which techniques are allowed, and when testing may happen. Anything outside that agreement is off limits. Cloud providers publish their own policies on what customers may test, so a pen test of cloud resources should always check the provider’s current rules first.

Pen test versus vulnerability scan

A vulnerability scan is broad and automated: software checks many systems against a catalogue of known weaknesses and produces a list. A penetration test is deep and largely manual: a person chains weaknesses together, uses judgement, and tries to prove real impact. The two are complementary rather than rivals.

  • Vulnerability scan — automated, wide coverage, finds known issues, can be run often, may include false positives.
  • Penetration test — human-led, targeted depth, attempts exploitation, shows real-world impact, usually run periodically or after major changes.
  • Together — scans keep watch continuously for known issues, while a pen test checks what a determined person could actually do. Our what is Amazon Inspector explainer covers an automated scanning service on AWS.

The usual phases

Methodologies differ in detail, but most tests follow the same shape at a beginner level:

  1. Reconnaissance — gathering information about the target, from public sources and from the system itself.
  2. Scanning — identifying live systems, services and likely weak points.
  3. Exploitation — attempting to use those weaknesses to gain access, within the agreed scope.
  4. Reporting — documenting what was found, how it was reached, how serious it is and how to fix it.

Black, grey and white box testing

The three styles describe how much the tester is told in advance. In black box testing the tester knows almost nothing, like an outside attacker. In white box testing they have full knowledge, such as architecture diagrams and source code, which allows a more thorough review. Grey box sits in between, often giving the tester the access of an ordinary user. None is better in general; the right choice depends on the question you want answered.

Where it fits in cloud security

Pen testing is one practice within broader cloud security, alongside access control, encryption and monitoring, and our what is cloud security article sets out the wider picture. A test is only as useful as what happens next: findings feed fixes, and attempts that were noticed or missed show how well monitoring works. That is where a SIEM comes in, which our what is a SIEM explainer covers. Our /revision library covers the security syllabuses for ISC2 Certified in Cybersecurity and AWS Certified Security – Specialty lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
SCS-C03CC

Questions, answered

It is an authorised, simulated cyberattack on a system, run by a security professional to find and demonstrate exploitable weaknesses before a real attacker does. The tester attacks only what the owner has agreed, then reports what they found and how to fix it.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
What is phishing? How it works and how to spot it
Cloud basics
What is public key infrastructure (PKI)?
Cloud basics
What is ransomware? How it works and how to protect against it
Cloud basics
What is social engineering? Common techniques and defences