InterviewSolution
| 1. |
How Much Information Does Redteam Pentesting Need From Us? |
|
Answer» The type and amount of information needed varies with the kind of penetration test that is to be conducted. The TWO concepts mentioned most often are blackbox and whitebox tests. UNFORTUNATELY, those terms are not defined by a standard and can therefore mean different things, DEPENDING on who you talk to. RedTeam Pentesting usually recommends a whitebox test. Penetration tests performed as complete blackbox tests always suffer from the fact that third parties MIGHT get involved without their explicit consent. Providing technical information in a whitebox test scenario before the test starts also allows the penetration testers to detect security vulnerabilities that are of importance to your COMPANY even faster and more efficiently. It should always be acted on the assumption that real, serious attackers are able to obtain the necessary information prior to their attacks, or can procure it in time. A precise determination about what information is necessary to conduct an efficient test is done individually for every client during a preliminary meeting. The type and amount of information needed varies with the kind of penetration test that is to be conducted. The two concepts mentioned most often are blackbox and whitebox tests. Unfortunately, those terms are not defined by a standard and can therefore mean different things, depending on who you talk to. RedTeam Pentesting usually recommends a whitebox test. Penetration tests performed as complete blackbox tests always suffer from the fact that third parties might get involved without their explicit consent. Providing technical information in a whitebox test scenario before the test starts also allows the penetration testers to detect security vulnerabilities that are of importance to your company even faster and more efficiently. It should always be acted on the assumption that real, serious attackers are able to obtain the necessary information prior to their attacks, or can procure it in time. A precise determination about what information is necessary to conduct an efficient test is done individually for every client during a preliminary meeting. |
|