Penetration Test
Also known as: Pentest · Security Test
A penetration test is an authorized, simulated attack carried out by specialists to uncover exploitable vulnerabilities in real systems.
A penetration test, or pentest, is a simulated attack on a system, network, or application, carried out by specialists with explicit permission and a clearly defined scope. The goal is to find weaknesses before a real attacker does, and to check whether a gap can actually be exploited.
In practice, testers try to break into a system using the same methods a real attacker would – an outdated software version, a misconfigured firewall rule, a weak password – and document every step along the way. The result is a report listing the vulnerabilities found, how exploitable they actually turned out to be, and concrete guidance on fixing them.
A common misconception is treating a penetration test as the same thing as an automated vulnerability scan. A scan lists known, potential weaknesses based on signatures; a penetration test has a human verify by hand whether any of those actually lead to access.
What it means in practice
For a business, a penetration test shows where a real attack surface exists instead of just delivering a theoretical list of possible weaknesses. It's most valuable after major changes to a network or applications, or before new, externally reachable systems go live. NDVDL organizes penetration tests for businesses and translates the results into concrete, actionable steps.
Is this handled properly at your site?
We look at how it actually stands with you — and say honestly whether anything needs doing.
Related terms
All termsA term from your quote missing here?
Send us the passage you do not follow. We will explain it — with no obligation to order anything.