# What is Penetration Testing?

> Penetration testing is an authorized, time-bounded security assessment in which skilled testers attempt to identify and safely exploit weaknesses within an agreed scope.

- Canonical URL: https://yellowcube.eu/glossary/penetration-testing/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The purpose is to demonstrate plausible attack paths and impact, test defensive assumptions, and provide evidence that supports remediation.

A professional test begins with rules of engagement covering targets, methods, credentials, prohibited actions, data handling, communications, safety, and emergency contacts. Findings should explain the exploited condition, evidence, business relevance, limitations, and how to verify the fix — not merely list scanner output.

### Key points

- **Possible scopes:** Network, application, API, cloud, wireless, mobile, identity, physical, or social-engineering controls.
- **Testing modes:** External or internal, with agreed levels of tester knowledge and access. Labels such as black-, gray-, and white-box are common, but their exact meanings should be defined in the rules of engagement.
- **Primary value:** Can demonstrate how weaknesses may be combined and whether an attacker could achieve defined objectives.
- **Authorization boundary:** Technical reachability is not permission. Testing must be authorized by the responsible asset owner and account for cloud-provider terms, shared infrastructure, suppliers, tenants, and other affected third parties.
- **Important limitation:** Results reflect the agreed scope, time, tester approach, and environment state; absence of a finding is not proof of security.

### Related terms

[Vulnerability assessment](<https://yellowcube.eu/glossary/vulnerability-assessment/>) · [Red team](<https://yellowcube.eu/glossary/red-team/>) · [Breach and attack simulation (BAS)](<https://yellowcube.eu/glossary/breach-and-attack-simulation/>) · [Rules of engagement](<https://yellowcube.eu/glossary/rules-of-engagement/>) · [Cyber range](<https://yellowcube.eu/glossary/cyber-range/>) · [Hacking and ethical hacking](<https://yellowcube.eu/glossary/hacking-and-ethical-hacking/>) · [Bug bounty](<https://yellowcube.eu/glossary/bug-bounty/>)

### Sources

[NIST SP 800-115: Technical Guide to Security Testing and Assessment](https://csrc.nist.gov/pubs/sp/800/115/final) · [NIST SP 800-53r5, control CA-8](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

