Security+ Lesson

Penetration Testing Types for Security+

Last updated: 6/10/2026

Short answer

Penetration testing is an authorized assessment, so rules of engagement and permission matter even though they are owned by third-party risk when vendors are involved. The type of test changes what the organization learns. Physical testing evaluates facility and physical access controls. Offensive testing emphasizes whether attackers can achieve objectives. Defensive testing emphasizes whether monitoring, alerting, triage, and response work. Integrated testing uses both perspectives so the organization can evaluate end-to-end readiness.

Why it appears on the exam

SY0-701 5.5: Compare physical, offensive, defensive, integrated, known-environment, partially known-environment, unknown-environment, passive recon, and active recon testing.

Key concepts

Concept 1

Required terms

Penetration testing: authorized security testing that attempts to find and validate exploitable weaknesses. Physical penetration test: authorized attempt to test physical controls such as facility access, badge processes, locks, guards, or restricted areas. Offensive test: assessment focused on attacker-style actions to compromise targets or demonstrate impact. Defensive test: assessment focused on how defenders detect, respond, and improve controls during or after testing.

Example

Testers try to enter a restricted office by following employees and checking badge process weaknesses. This is a physical penetration test.

Concept 2

How Penetration Testing Types works

Penetration testing is an authorized assessment, so rules of engagement and permission matter even though they are owned by third-party risk when vendors are involved. The type of test changes what the organization learns. Physical testing evaluates facility and physical access controls. Offensive testing emphasizes whether attackers can achieve objectives. Defensive testing emphasizes whether monitoring, alerting, triage, and response work. Integrated testing uses both perspectives so the organization can evaluate end-to-end readiness.

Example

A red team tries to compromise a web application while defenders are not told the exact timing. This is offensive testing.

Concept 3

Common confusion

Learners often confuse known environment with active reconnaissance. The correction: known/partially known/unknown describes how much information testers start with; active/passive describes how reconnaissance is performed.

Example

A test is designed to measure whether the SOC detects and escalates simulated attacker behavior. This is defensive testing.

Concept 4

What to recognize

Match penetration testing type to scenario cue; Distinguish physical, offensive, defensive, and integrated tests; Compare known, partially known, and unknown environment tests; Distinguish passive and active reconnaissance.

Example

Testers receive network ranges and architecture diagrams before testing. This is a known-environment test.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.A security team sees this situation: Testers try to enter a restricted office by following employees and checking badge process weaknesses. Which concept applies?

Q2.A security question includes this clue: Testers try to enter a restricted office by following employees and checking badge process weaknesses. Which term is being tested?

Q3.A Security+ scenario describes this situation: A test is designed to measure whether the SOC detects and escalates simulated attacker behavior. Which answer fits best?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8