Comptia Security+ Domain 1
Comptia Security+ Domain 1
CompTIA Security+
SY0-501
CompTIA Security+
Domain 1 –
Threats, Attacks and Vulnerabilities
Penetration Testing
A penetration test, or a pen test, is an authorized,
simulated attack on a computer system, performed to
evaluate the security of the system by actively
exploiting found vulnerabilities.
aka Ethical Hacking
Process
Information Gathering /
Discovery / Reconnaissance
Types of testing
● Black Box: The tester has absolutely no knowledge of the
system and is functioning in the same manner as an outside
attacker.
● White Box: The tester has significant knowledge of the
system. This simulates an attack from an insider—a rogue
employee.
● Gray Box: This is a middle ground between the first two types
of testing. In gray box testing, the tester has some limited
knowledge of the target system.
Types of testing
Sample question
Of the following types of testing steps, which
focuses on directly scanning a system, using
techniques such as port scans, network mapping,
ICMP scans to identify potential weaknesses?
A. Operational reconnaissance
B. Active reconnaissance
C. Passive reconnaissance
D. Initial exploitation
Sample question
In initially conducting a penetration test, you find
vulnerabilities on a separate, less secure server on
the same network as the one you’re investigating.
You use access to that server to then attack the
target servers. This type of exploit is know as:
A. Escalation of privileges
B. Pivoting
C. Active reconnaissance
D. Persistence
CompTIA Security+
Domain 1 –
Threats, Attacks and Vulnerabilities
1.4 Explain penetration testing concepts