There is a considerable amount of confusion in the industry regarding the differences between vulnerability scanning and penetration testing, as the two phrases are often used interchangeably. However, their meaning and implications are very different. A vulnerability assessment simply identifies and reports noted vulnerabilities, whereas a penetration test (Pen Test) attempts to exploit the vulnerabilities to determine whether unauthorized access or other malicious activity is possible.
Penetration testing typically includes network penetration testing and application security testing; it also includes controls and processes around the networks and applications and should occur from both outside the network trying to come in (external testing) and from inside the network.
QUESTION:
Given this information, review the two links on how Kali Linux is often used in penetration testing, the tools it contains, and how it can assist a penetration tester to identify vulnerabilities in the network:
https://linuxhint.com/penetration_testing_kali_linux/
https://tools.kali.org/
Once you have done that, answer the following questions as though you were an internal or external penetration test firm assisting a company in strengthening their systems, framework, and network.
- How does the penetration test differ from other types of security testing—such as a vulnerability assessment?
- What is your process for performing the penetration test?
- Discuss the process and tools that would be used.
- How will you protect the data during and after testing?
- How will you ensure the availability of the systems and services while the test is taking place?