🦹Pentesting Fundamentals

Learn the important ethics and methodologies behind every pentest

https://tryhackme.com/room/pentestingfundamentalsarrow-up-right

Room Attributes
Value

Subscription Required

False [Free]

Type

Walkthrough

Difficulty

Info

Tags

Cybersecurity, Framework, Penetration Testing, Ethics

Task 1 What is Penetration Testing?

Read me!

circle-check

Task 2 Penetration Testing Ethics

You are given permission to perform a security audit on an organisation; what type of hacker would you be?

circle-exclamation
chevron-rightReveal Flag 🚩hashtag

🚩White Hat

You attack an organisation and steal their data, what type of hacker would you be?

chevron-rightReveal Flag 🚩hashtag

🚩Black Hat

What document defines how a penetration testing engagement should be carried out?

chevron-rightReveal Flag 🚩hashtag

🚩Rules of Engagement

Task 3 Penetration Testing Methodologies

What stage of penetration testing involves using publicly available information?

chevron-rightReveal Flag 🚩hashtag

🚩Information Gathering

If you wanted to use a framework for pentesting telecommunications, what framework would you use? Note: We're looking for the acronym here and not the full name.

chevron-rightReveal Flag 🚩hashtag

🚩OSSTMM

What framework focuses on the testing of web applications?

chevron-rightReveal Flag 🚩hashtag

🚩OWASP

Task 4 Black box, White box, Grey box Penetration Testing

You are asked to test an application but are not given access to its source code - what testing process is this?

chevron-rightReveal Flag 🚩hashtag

🚩Black Box

You are asked to test a website, and you are given access to the source code - what testing process is this?

chevron-rightReveal Flag 🚩hashtag

🚩White Box

Task 5 Practical: ACME Penetration Test

Complete the penetration test engagement against ACME's infrastructure.

chevron-rightReveal Flag 🚩hashtag

🚩THM{PENTEST_COMPLETE}

Last updated