Chapter 6
Penetration Testing
IN THIS CHAPTER
Testing your network to see how secure it is
Understanding what a penetration test looks like
Looking at some of the tools used by penetration testers
Preparing yourself for what the testers will find
A penetration test, also known as a pentest, is an attempt to gain access to a computer system in an effort to discover vulnerabilities in the system. It’s a form of hacking called ethical hacking (hacking that is done for good purposes by the good guys to prevent the bad guys from doing it for nefarious purposes).
A pentest is not the same thing as conducting a thorough review of your cybersecurity practices. A security review involves confirming that your organization is using the best security practices it can. For example, you should
- Review your Microsoft Windows update policies to ensure that they’re working and that all your computers are up-to-date.
- Confirm that multifactor authentication (MFA) is in place for all your users and that everyone has enrolled at least one MFA factor.
- Confirm that your antivirus software is working ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access