# Penetration test

> An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.

The word that does the work is authorised. A pen test begins with a written scope: what is in, what is off limits, what happens if something falls over, and who gets the call. Without that document the same activity is a crime, and the paperwork is not a formality — it is the thing that makes the exercise possible.

What distinguishes a test from a scan is that a human tries to chain things. A scanner reports that a version is outdated and that a form reflects input; a tester notices that one gives them a session and the other gives them somebody else's, and writes up the path between them with reproduction steps. The finding that matters is usually a combination, and combinations are what automation is worst at.

Expect a report you can act on: each finding with steps to reproduce it, an honest severity, and what it means in business terms. A four-hundred-item scanner export with the informational findings left in is not a penetration test.

## Related terms

- https://dfieldsolutions.com/en/glossary/red-team.md
- https://dfieldsolutions.com/en/glossary/purple-team.md
- https://dfieldsolutions.com/en/glossary/security-audit.md
- https://dfieldsolutions.com/en/glossary/threat-model.md

---

Source: https://dfieldsolutions.com/en/glossary/penetration-test
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
