Penetration Testing Methodology
What is Penetration Testing?
A penetration test (pentest) is an authorised, planned attempt to break into a system, so that the owner can find and fix weaknesses before a real attacker does. The people who do it are ethical hackers. They use the same techniques as criminals, but with written permission, agreed limits and the goal of improving security.
The difference between a pentester and a criminal is not skill. It is authorisation, scope and intent.
Legal note: Testing without written permission is a crime under laws such as Nigeria's Cybercrimes Act 2015, the UK Computer Misuse Act 1990 and the US Computer Fraud and Abuse Act. "I was only checking" is not a defence. Always get a signed agreement first.
Types of Test
| Type | What the tester knows |
|---|---|
| Black box | Nothing, like an outside attacker |
| Grey box | Some information, such as a normal user account |
| White box | Full details: source code, diagrams, admin access |
They can target networks, web and mobile apps, wireless, cloud, or people (social engineering). A red team exercise goes further, simulating a real adversary over weeks and testing the defenders too.
The Phases
Most professional methodologies (PTES, OSSTMM, NIST SP 800-115, OWASP WSTG) follow the same flow:
1. Planning and scoping
Agree the scope (which systems, IP ranges, apps), the rules of engagement (allowed techniques, testing hours, no denial of service), emergency contacts, and get the signed authorisation ("get out of jail free" letter). Without this you must not begin.
2. Reconnaissance
Gather information about the target. Passive recon uses public sources without touching the target (search engines, DNS records, social media, Shodan). Active recon contacts the target directly. You will practise this in the next lesson.
3. Scanning and enumeration
Find live hosts, open ports, services, versions and users. Tools: Nmap, Nessus/OpenVAS, Nikto. The output is a map of possible weaknesses.
4. Exploitation (gaining access)
Try to use a weakness to gain access, for example a known vulnerability, weak password or misconfiguration. The aim is to prove impact, not to cause damage.
5. Post-exploitation
Show what an attacker could do next: read data, escalate privileges, move to other systems (lateral movement). Handle any data carefully and stay in scope.
6. Reporting and clean-up
The most important phase for the client. Document every finding with evidence, risk rating and fix advice. Remove any tools, accounts or files you created. Present the results, and later retest to confirm fixes.
Plan -> Recon -> Scan -> Exploit -> Post-exploit -> Report -> Retest
The Ethics That Go With It
- Stay in scope. If you find a system that is not listed, stop and ask.
- Do no harm. Avoid actions that could crash production or destroy data. Agree how to handle sensitive data such as customer records.
- Confidentiality. Findings are private to the client.
- Honesty. Report what you found, including mistakes you made.
- Responsible disclosure. If you find a flaw outside an engagement, report it through the owner's official channel and never publish it before it is fixed.
A Nigerian and Global View
Banks, fintechs, telcos and government agencies in Nigeria commission penetration tests to meet regulatory expectations and customer trust. Standards such as PCI DSS require regular testing of systems that handle card data, and cloud-first companies in Europe and North America do the same. Nigerian security professionals also work remotely for international clients and bug-bounty platforms, which makes a solid methodology and professional habits an advantage in the global job market.
Try It: Put the Phases in Order
In the editor on the right, click the six phases in the correct order. Then think about which phase each of your recent labs belonged to.
Try it yourself
Key Takeaways
- A penetration test is an authorised attempt to find and prove weaknesses so they can be fixed. Authorisation and scope are what make it legal.
- Black, grey and white box describe how much the tester knows. A red team simulates a real adversary over a longer time.
- The phases are planning and scoping, reconnaissance, scanning and enumeration, exploitation, post-exploitation, then reporting, clean-up and retest.
- Ethics matter: stay in scope, do no harm, protect client data, be honest and use responsible disclosure.
- Reporting is the most valuable phase for the client. A test without a clear report and retest does not improve security.
Quick Quiz
1.What is the single most important thing that separates a penetration tester from a criminal?
2.In a grey box test, what does the tester have?
3.During testing you discover a server that is not listed in the scope. What should you do?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx