Penetration Testing mailing list archives

Why Penetration Test?


From: tarunthenut () gmail com
Date: 2 Jun 2005 06:29:34 -0000

I was wondering the usefulness of a penetration testing against vulnerability assessment for a company. 

Scenario A
Cosultant "A  is employed to perform a vulnerability assessment and the result is tabulated based on the business risk 
these vulnerabilities pose.

Scenario B
Cosultant "B is employed to perform a Penetration Test, discovers 10 vulnerabilities and is able to show exploit of 5 
vulnerabilities.

Scenario C
Cosultant "C" is employed to perform a Penetration Test, discovers 10 vulnerabilities and is able to show exploit of 7 
vulnerabilities.

Which scenario would have more usefulness to the company? it is ovbious that the result of a PT would depend and vary 
from skill of a consultant to another? 


Current thread: