D9 · PenTest+

What is pen test methodology?

Standard pen test phases: PlanningReconnaissanceScanning/EnumerationExploitationPost-ExploitationReporting.
PTES (Penetration Testing Execution Standard) and OSSTMM are formal methodologies. Always start with written authorization. Document everything — reports must be reproducible. Post-exploitation demonstrates real business impact (not just technical access). Reporting is the deliverable clients pay for.
← Back to Glossary Practice Questions →