Penetration Testing Phases (Coordination – 2)

Estimated read time 3 min read

We have examined the general structure of the coordination processes, which is the 1st Phase during the Penetration Test preparations, in our article in this link. Now, we will examine in detail one of the issues that will be discussed during the meeting.

During the determination of the Scope within the coordination processes we mentioned, the security company providing the service asks some questions in order to reveal the purpose of the company receiving the service. Below, we will explain the questions that may be asked depending on the type of test to be performed. The company that will receive the service should prepare for the answers to these questions before the coordination meeting, in order to avoid any uncertainties that may arise during the meeting.

Network Test

  1. Why will the company have its system personnel perform network testing?
  2. Is network testing done out of obligation to meet a standard?
  3. During which time periods does the company find it more appropriate to actively conduct the test?
    1. During business hours?
    2. After hours?
    3. On weekends?
  4. How many total IP addresses will be tested?
    1. How many internal network IP addresses will be tested?
    2. What is the number of external network IP addresses to test?
  5. Is there a Firewall, IPS / IDS or Load Balancer system in the Network topology to be tested?
  6. If the system can be logged in, how will the testing team act?
    1. Will a local vulnerability scan be performed on the logged-in system?
    2. Will efforts be made to become the most authorized user in the system to which access is provided?
    3. Will dictionary attacks be performed to obtain passwords on the system that is being accessed?

Web Application Testing

  1. How many applications will be tested?
  2. How many login systems will be tested?
  3. How many static pages will be tested?
  4. How many dynamic pages will be tested?
  5. Will the source codes of the application to be tested be provided?
  6. Will any documentation regarding the application be provided?
    1. If the answer is yes, what are these documents?
  7. Will static analyzes be performed on the application?
  8. What are the other topics requested?

Wireless Network Test

  1. How many wireless networks are in the system?
  2. Which of these will be tested?
  3. Is there a wireless network in the system for guest use?
  4. What are the encryption techniques of wireless networks?
  5. Will users connected to guest networks be tested?
  6. What are the broadcast distances of wireless networks?
  7. How many people on average use these wireless networks?

Physical Security Tests

  1. What are the number and locations of testing venues?
  2. Is the testing location shared with other units?
  3. How many floors are there in the venue?
  4. Which of the floors are included in the scope?
  5. Are there security guards at the venue that you have to pass through?
  6. What are the equipment status and powers of the officers?
  7. Is security service received from a 3rd party company?
  8. How many entrances does the venue have?
  9. Are there any video recording security measures?
  10. Will the testing team test access to video recorders?
  11. Is there an alarm system?

Social Engineering Test

  1. Will an email address list be provided for Social Engineering tests?
  2. Will a list of phone numbers be provided for Social Engineering tests?
  3. Is physical access to the system granted as a result of social engineering?

Questions related to the above mentioned tests can be expanded. It is also possible to differentiate based on experience.

İbrahim Korucuoğlu

Yazar, bilişim ve teknoloji alanında derlediği faydalı içerikleri bu blogta paylaşmaktadır.