官术网_书友最值得收藏!

Scoping criteria

We will now see an example questionnaire for the scoping criteria. First, we will start with questions that will be derived from a white-box tester only to gain intimate knowledge of the network for testing:

  • What are the subnets and/or IP addresses in the scope of this test?
  • Are there any systems that are out of scope?
  • Are there security devices within the network? (This is important because these devices may block access into an environment, and that will prevent testing the system correctly)
  • Is there any type of important data held or transferred within the environment?

Finally, if the penetration tester is using more of a black-box mentality, then these questions will be relevant for them, as well as the white-box testers:

  • Is guest access in scope as well?
  • Which corporate SSIDs are in scope?
  • What are the physical locations in scope for the test (if there are multiple locations)? Are all locations/networks dedicated, or are they shared with another company (for example, shared hosting or some cloud environments)?
This list is by no means complete or comprehensive. It is important for you, as a penetration tester, to figure out what questions you feel are relevant for your particular engagement. The preceding list contains some of the required questions, based on my experience.
主站蜘蛛池模板: 海南省| 德钦县| 东方市| 济宁市| 公安县| 温宿县| 泽州县| 大庆市| 柳州市| 镶黄旗| 铜梁县| 南投县| 公主岭市| 平陆县| 浦江县| 公主岭市| 曲阜市| 阿瓦提县| 德兴市| 汉沽区| 苗栗县| 且末县| 谢通门县| 五河县| 鄄城县| 比如县| 白沙| 江西省| 古丈县| 科技| 东兰县| 中阳县| 修文县| 赤城县| 房产| 罗甸县| 修水县| 嵩明县| 新津县| 阳信县| 论坛|