官术网_书友最值得收藏!

Scoping criteria

We will now see an example questionnaire for the scoping criteria. First, we will start with questions that will be derived from a white-box tester only to gain intimate knowledge of the network for testing:

  • What are the subnets and/or IP addresses in the scope of this test?
  • Are there any systems that are out of scope?
  • Are there security devices within the network? (This is important because these devices may block access into an environment, and that will prevent testing the system correctly)
  • Is there any type of important data held or transferred within the environment?

Finally, if the penetration tester is using more of a black-box mentality, then these questions will be relevant for them, as well as the white-box testers:

  • Is guest access in scope as well?
  • Which corporate SSIDs are in scope?
  • What are the physical locations in scope for the test (if there are multiple locations)? Are all locations/networks dedicated, or are they shared with another company (for example, shared hosting or some cloud environments)?
This list is by no means complete or comprehensive. It is important for you, as a penetration tester, to figure out what questions you feel are relevant for your particular engagement. The preceding list contains some of the required questions, based on my experience.
主站蜘蛛池模板: 绥棱县| 当阳市| 开平市| 黄山市| 吴川市| 天祝| 石渠县| 邵东县| 四会市| 太谷县| 宝兴县| 当涂县| 轮台县| 德昌县| 石楼县| 察雅县| 固始县| 根河市| 西华县| 麟游县| 瑞安市| 曲阜市| 黄骅市| 郴州市| 伽师县| 安溪县| 赤水市| 台中市| 湘潭县| 尼勒克县| 霞浦县| 吴旗县| 鄂温| 蒙城县| 兴国县| 宜昌市| 南靖县| 三明市| 朝阳市| 芦溪县| 闽清县|