Penetration Testing Types for Security+
Short answer
Penetration testing is an authorized assessment, so rules of engagement and permission matter even though they are owned by third-party risk when vendors are involved. The type of test changes what the organization learns. Physical testing evaluates facility and physical access controls. Offensive testing emphasizes whether attackers can achieve objectives. Defensive testing emphasizes whether monitoring, alerting, triage, and response work. Integrated testing uses both perspectives so the organization can evaluate end-to-end readiness.
Why it appears on the exam
SY0-701 5.5: Compare physical, offensive, defensive, integrated, known-environment, partially known-environment, unknown-environment, passive recon, and active recon testing.
Key concepts
Concept 1
Required terms
Penetration testing: authorized security testing that attempts to find and validate exploitable weaknesses. Physical penetration test: authorized attempt to test physical controls such as facility access, badge processes, locks, guards, or restricted areas. Offensive test: assessment focused on attacker-style actions to compromise targets or demonstrate impact. Defensive test: assessment focused on how defenders detect, respond, and improve controls during or after testing.
Example
Testers try to enter a restricted office by following employees and checking badge process weaknesses. This is a physical penetration test.
Concept 2
How Penetration Testing Types works
Penetration testing is an authorized assessment, so rules of engagement and permission matter even though they are owned by third-party risk when vendors are involved. The type of test changes what the organization learns. Physical testing evaluates facility and physical access controls. Offensive testing emphasizes whether attackers can achieve objectives. Defensive testing emphasizes whether monitoring, alerting, triage, and response work. Integrated testing uses both perspectives so the organization can evaluate end-to-end readiness.
Example
A red team tries to compromise a web application while defenders are not told the exact timing. This is offensive testing.
Concept 3
Common confusion
Learners often confuse known environment with active reconnaissance. The correction: known/partially known/unknown describes how much information testers start with; active/passive describes how reconnaissance is performed.
Example
A test is designed to measure whether the SOC detects and escalates simulated attacker behavior. This is defensive testing.
Concept 4
What to recognize
Match penetration testing type to scenario cue; Distinguish physical, offensive, defensive, and integrated tests; Compare known, partially known, and unknown environment tests; Distinguish passive and active reconnaissance.
Example
Testers receive network ranges and architecture diagrams before testing. This is a known-environment test.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.A security team sees this situation: Testers try to enter a restricted office by following employees and checking badge process weaknesses. Which concept applies?
Q2.A security question includes this clue: Testers try to enter a restricted office by following employees and checking badge process weaknesses. Which term is being tested?
Q3.A Security+ scenario describes this situation: A test is designed to measure whether the SOC detects and escalates simulated attacker behavior. Which answer fits best?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8