Penetration Testing
Penetration testing is a security testing technique in which authorized testers simulate real-world attacks to identify exploitable vulnerabilities.
“A type of dynamic application security testing to assess weaknesses and vulnerabilities without causing harm by mimicking an attacker.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Penetration Testing?
Penetration testing evaluates how effectively security controls resist attacks by attempting to compromise systems using attacker techniques.
Authorized activity: Conducted with explicit permission.
Realistic attacks: Simulates techniques used by malicious attackers.
Risk assessment: Helps prioritize security improvements.
Real World Example
A regulated product team is preparing a release where Penetration testing appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.
The risk is that the team treats Penetration testing as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.
The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Penetration testing and similar ideas.
The page becomes useful in practice because Penetration testing is connected to a specific testing decision, not memorized as a detached definition.
Practice Questions
Question 1
Which statement BEST describes Penetration testing in the context of ISTQB terminology?
Question 2
A tester needs to explain Penetration testing to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Penetration Testing. Test your understanding with topic-specific questions in our Mock Exams.