官术网_书友最值得收藏!

Status meeting and reports

Communication is key for a successful penetration test. Regular meetings should be scheduled between the testing team and the client organization and routine status reports issued by the testing team. The testing team should present how far they have reached and what vulnerabilities have been found up to that point. The client organization should also confirm whether their detection systems have triggered any alerts resulting from the penetration attempt. If a web server is being tested and a WAF was deployed, it should have logged and blocked attack attempts. As a best practice, the testing team should also document the time when the test was conducted. This will help the security team in correlating the logs with the penetration tests.

WAFs work by analyzing the HTTP/HTTPS traffic between clients and servers, and they are capable of detecting and blocking the most common attacks on web applications.
主站蜘蛛池模板: 乌审旗| 龙山县| 浮山县| 陇南市| 万全县| 合肥市| 巫溪县| 阿拉尔市| 汉寿县| 陇川县| 深泽县| 永寿县| 宝鸡市| 简阳市| 兴化市| 沁阳市| 银川市| 特克斯县| 新巴尔虎左旗| 茌平县| 赞皇县| 恩平市| 尼玛县| 常宁市| 怀集县| 儋州市| 吐鲁番市| 锦州市| 荣昌县| 华容县| 和田县| 平阳县| 乡宁县| 卢氏县| 勐海县| 育儿| 永修县| 湄潭县| 梅河口市| 丰都县| 十堰市|