What Is Penetration Testing?
Organizations run penetration tests for four main reasons, to:
- Find exploitable weaknesses before an attacker does, especially in internet-facing applications, APIs, and cloud configurations. Breaches carry financial, reputational, and legal consequences, and testing is how you learn whether your defenses hold before someone else does.
- Separate real risk from noise. Scanners produce long lists. A pentest shows which items can actually be used.
- Meet compliance and customer requirements. Frameworks such as PCI DSS and SOC 2, and many customer contracts, expect penetration testing. See Is penetration testing required for compliance?
- Verify that fixes worked. A retest confirms a vulnerability is closed, not just marked closed.
Who Performs a Penetration Test?
A pentester is an experienced security professional who understands both how defenses are built and how to get around them. Quality depends on who they are and how they are vetted. Synack’s testers are the Synack Red Team, a global community of vetted security researchers who complete a screening process before joining testing programs. Learn more about the Synack Red Team.
How Does a Penetration Test Work?
Most engagements follow the same stages, whether they run once a year or continuously:
- Planning and scoping. Define the goal: break in at all, find as many exploitable weaknesses as possible, or reach a specific asset such as sensitive data. Set assets, testing windows, credentials, rules of engagement, and whether defenders will know the test is underway.
- Reconnaissance. Gather information about the target and its attack surface, then map a preliminary strategy.
- Gaining access. Examine possible entry points and choose techniques, such as SQL injection, brute-force attacks, or social engineering.
- Maintaining access and moving laterally. Once in, testers try to stay in long enough to reach their objective and see how far access extends. This is how a pentest shows impact, not just entry.
- Reporting. Deliver reproducible findings in language stakeholders can follow, with remediation guidance.
- Verification. A test is not finished until remediation is confirmed as implemented and working.
For a deeper walk-through, see How does penetration testing work?
What Are the Types of Penetration Testing?
There are two main ways to classify tests: what is tested, and how much testers know going in.
By target
The right test depends on what you are protecting. Most programs combine several types.
| Type | What it tests | Typical fit |
| Web application | Authentication, authorization, business logic, injection flaws. The OWASP Web Security Testing Guide is a common reference. | Customer-facing and internal web apps |
| API | Broken object-level authorization, excessive data exposure, weak authentication | Mobile back ends, partner and microservice APIs |
| Network (external / internal) | Exposed services, segmentation, credential weaknesses | Perimeter and internal infrastructure |
| Cloud | Misconfigured identity, storage, and workloads in AWS, Azure, or GCP | Cloud-hosted production environments |
| Social engineering | Whether staff can be manipulated into giving access | Phishing resilience, physical access |
| AI and LLM application | What a manipulated model can reach through its tools and data | Applications with agents or retrieval pipelines |
There is no single best approach for web applications, APIs, networks, and cloud together. Start with the assets that are internet-facing, hold sensitive data, or change most often, then expand scope. For the full breakdown, see What types of penetration testing are there?
By tester knowledge
| Approach | What testers get | What it simulates |
| Black-box | No access or information beyond public sources | The closest match to an outside attacker. Testers may get a specific goal, such as reaching a particular data set. |
| Grey-box | Partial access, such as limited credentials | A low-privilege user, employee, or vendor acting maliciously |
| White-box | Credentials and usually full system access | Deep analysis of internal controls and processes, without time spent breaking in |
Deciding what access and information testers receive is one of the first scoping decisions, and it shapes both cost and findings. See how scoping affects your results.
Manual and automated testing
Automated testing runs predetermined checks, often based on known weakness sets such as the OWASP Top 10. It is fast, needs fewer people, and suits known vulnerabilities and a broad read on posture. Manual testing lets people adapt like an attacker, chain weaknesses, and judge the damage a breach could cause, including lateral movement. Most mature programs use both. Automation supplies coverage and cadence, and human testing answers whether a weakness is actually exploitable.
What Is the Difference Between a Penetration Test and a Vulnerability Scan?
A vulnerability assessment searches for known weaknesses, usually with automated tools, and is relatively quick and inexpensive. It reports what might be wrong and suggests fixes, but it does not try to exploit anything or measure how damaging an exploit would be. A penetration test tries to use those weaknesses and reports what worked. To extend the burglar comparison, a scan checks that the known doors are locked. A pentest sends someone to find the faulty crawl space screen or talk their way in dressed as a contractor.
| Vulnerability scan | Penetration test | |
| Question answered | What could be vulnerable? | What can an attacker actually do? |
| Method | Automated matching against known issues | Automated tooling plus manual, adversarial testing |
| Output | List of potential issues, often with false positives | Validated findings with reproduction steps |
| Cadence | Frequent, often continuous | Scoped engagements, or continuous when delivered as a service |
Use a scan for an overall picture of posture, then follow it with a penetration test. If you need providers that find exploitable issues rather than scanner output, ask how each one proves exploitability and whether humans validate the results. See What is the difference between vulnerability assessment and penetration testing?
What Should a Penetration Test Report Include?
A useful report lets an engineer reproduce each finding and lets an auditor see what was tested. Look for:
- Scope, dates, and methodology, including what was not tested
- Each finding with severity, affected asset, and business impact
- Step-by-step reproduction evidence such as requests, responses, and screenshots
- Remediation guidance specific to the environment
- Retest results showing which fixes were confirmed
A report that lists issues without evidence of exploitation reads like a scan export. Post-test analysis should also flag weak or ineffective policies and controls, not only individual bugs. For more detail, see What should a penetration test report include?
How Often Should You Run a Penetration Test?
Frequency depends on your size, business, and security requirements. Large organizations are frequent targets and need to test regularly. At minimum, test annually and after any significant change, such as patches, security policy changes, hardware or software upgrades, a major release, a new architecture, or a new location. Some standards, including PCI DSS, set a minimum cadence, and some customer contracts require formally scoped annual tests. Environments that change weekly outpace a once-a-year test, which is why many teams add continuous testing between scoped assessments. Continuous testing complements formal annual assessments where those are required, and does not replace them. See How often should organizations perform penetration testing?
How Do You Choose a Penetration Testing Provider?
Compare providers on evidence and accountability, not on tool lists:
- Exploit validation. Does the provider prove exploitability, or infer it from version strings and scanner output?
- Tester vetting. Who performs the work, and under what agreements and scope controls?
- Coverage for your stack. Web, API, cloud, and AI applications each need different skills.
- Remediation support. Does the engagement include fix guidance and retesting?
- Delivery model. Point-in-time project, or ongoing testing as scope changes?
Synack combines Sara, its AI pentesting agent, with the Synack Red Team for continuous, human-validated penetration testing, so AI-driven coverage is paired with human validation of exploitable findings. Coverage depends on the scope agreed for each engagement.


