What is Penetration Testing?

Penetration testing is an authorized, simulated attack against a system, network, or application performed to find exploitable security weaknesses before a real attacker does.

Unlike an automated vulnerability scan, a penetration test is carried out by a skilled tester (or team) who actively tries to chain weaknesses together — a misconfigured permission plus a leaked credential plus an outdated library — the way a real adversary would, rather than just listing known CVEs. Tests are typically scoped as black-box (no internal knowledge), white-box (full access to source and architecture), or gray-box (partial knowledge), and cover network, web application, API, cloud configuration, and sometimes social-engineering vectors. A test concludes with a report ranking findings by exploitability and business impact, plus proof-of-concept steps so engineering can reproduce and verify a fix rather than guessing at the report's meaning. Many compliance frameworks (SOC 2, ISO 27001, PCI-DSS) require periodic penetration testing as evidence that security controls are tested under real adversarial conditions, not just documented on paper. Penetration testing is a point-in-time exercise, so it complements — but doesn't replace — continuous practices like dependency scanning, code review, and monitoring; a clean pen test result from six months ago says nothing about a vulnerability introduced last week.

In practice with Neotask

Neotask's own SOC 2 evidence layer tracks penetration test results and remediation status alongside the control matrix, so a finding against, say, an HMAC-verified route gets a tracked fix and a retest rather than living only in a PDF nobody revisits.

Related terms

Start free

Plans

Free

$0/mo

Download without a card and start for free.

Individual

$50/mo

The full personal agent platform for one person.

Enterprise

$200/mo

Multiple workspaces and capacity for larger teams.

Continue