官术网_书友最值得收藏!

Status meeting and reports

Communication is key for a successful penetration test. Regular meetings should be scheduled between the testing team and the client organization and routine status reports issued by the testing team. The testing team should present how far they have reached and what vulnerabilities have been found up to that point. The client organization should also confirm whether their detection systems have triggered any alerts resulting from the penetration attempt. If a web server is being tested and a WAF was deployed, it should have logged and blocked attack attempts. As a best practice, the testing team should also document the time when the test was conducted. This will help the security team in correlating the logs with the penetration tests.

WAFs work by analyzing the HTTP/HTTPS traffic between clients and servers, and they are capable of detecting and blocking the most common attacks on web applications.
主站蜘蛛池模板: 宝兴县| 合川市| 岐山县| 肇庆市| 拜泉县| 资溪县| 开平市| 中宁县| 昭苏县| 民勤县| 门源| 拜城县| 九龙坡区| 延寿县| 额济纳旗| 合水县| 儋州市| 孟津县| 磐石市| 舟曲县| 内乡县| 河北区| 罗田县| 靖州| 揭西县| 黔东| SHOW| 连平县| 枣强县| 池州市| 新蔡县| 乌兰浩特市| 岗巴县| 宾川县| 苏尼特左旗| 吴忠市| 安泽县| 吴川市| 梁河县| 什邡市| 隆昌县|