Pen testing sounds like one job until you actually look at what security teams test. A website needs a different approach from a mobile app. An internal company network has its own problems. And sometimes the tester is given almost nothing before starting.
External Pen Testing
An external pen test starts from outside the organisation. The tester looks at systems that an attacker on the internet could reach, such as a public website or exposed service.
They aren’t given a friendly map of the environment. Instead, they work with what an outsider could discover and try to identify a path into the organisation.
What Gets Tested?
• Public-facing applications are the obvious target, though the tester also checks exposed services that shouldn’t be sitting there.
• External infrastructure gets attention too. One forgotten system can be enough to create a problem.
The tester may examine login controls and look for weaknesses in the way the application handles user input. They may also test whether exposed systems can be used to move deeper into the environment.
Internal Pen Testing
Internal testing starts from inside the organisation. The tester could be given access similar to an employee, or they could begin with limited access and see how far it goes.
So the question changes. Instead of asking, “Can someone get in?” the test asks what happens after access already exists.
This is especially useful for understanding how well internal systems are separated. A compromised employee account shouldn’t automatically open every door.
Web, Mobile, and Network Pen Tests
Web application testing focuses closely on how a website behaves. Testers examine things such as authentication and session handling, then look for flaws that could expose data or allow unwanted actions.
Mobile pen testing follows a similar idea but looks at the mobile app and the way it communicates with backend services. The tester checks how information is stored and how the app handles requests.
Network testing focuses on network devices and services. It can reveal weak configurations or unnecessary exposure that isn’t obvious during normal day-to-day operations.
• Web applications are often the busiest area because users constantly interact with them, which gives attackers plenty to probe.
• Mobile apps have their own quirks. A badly handled token can matter far more than a small interface bug.
• Network testing gets into the infrastructure underneath everything, where one overlooked configuration can become surprisingly important.
Black Box, White Box, and Gray Box Testing
In a black box test, the tester has little information about the target. It closely resembles an outside attacker trying to figure things out from scratch.
White box testing goes the other direction. The tester receives detailed information about the environment or application. That lets them dig deeper because they don’t have to spend the entire engagement discovering basic details.
Gray box testing sits between those approaches. The tester gets some useful information but still has gaps to work through.