Types of Penetration Testing: Choosing the Right Engagement for Your Risk Profile
Penetration testing is not a single service — it is a category of security assessments with distinct methodologies, scopes, and objectives. Understanding the types available helps regulated organizations select the engagement that matches their compliance requirements, threat model, and security program maturity.
Every Engagement Starts With a Knowledge-Level Decision
Every penetration test operates within one of three knowledge-level frameworks that define how much information testers have about the target environment before the engagement begins. The choice affects the realism of the simulation, the efficiency of the engagement, and what the findings tell you about your defensive posture.
Black-Box Testing
Testers begin with no prior knowledge of the target — only what an external attacker could gather through open-source intelligence and active reconnaissance. This format most accurately simulates an opportunistic external attacker and is best suited for organizations validating mature perimeter controls under realistic conditions.
Gray-Box Testing
Testers receive partial information — network diagrams, application documentation, or user-level credentials — simulating an attacker who has gained an initial foothold. Gray-box is the most common format for compliance-driven testing, including PCI-DSS Requirement 11.4 and CMMC-aligned assessments.
White-Box Testing
Testers get full access to source code, architecture documentation, configurations, and administrative credentials. Not designed to simulate an attacker — designed to find every vulnerability with maximum efficiency. Best for pre-release application reviews, code audits, and configuration reviews where completeness matters most.
See how this applies to defense-contractor compliance in penetration testing for CMMC.
Penetration Testing by Target Environment
Beyond knowledge level, penetration tests are categorized by the environment or asset type they target. Each category requires different expertise, tools, and methodology.
Network Penetration Testing
Assesses firewalls, routers, switches, VPNs, and wireless infrastructure. External testing covers internet-facing systems; internal testing evaluates lateral movement, Active Directory weaknesses, and segmentation failures. The baseline engagement for most compliance programs.
Web Application Testing
Targets injection flaws, authentication weaknesses, authorization failures, business logic errors, and cryptographic issues, following the OWASP Testing Guide. Required for any organization with internet-facing applications handling sensitive data.
Mobile Application Testing
Evaluates iOS and Android client-side storage, inter-process communication, API security, and authentication under the OWASP Mobile Security Testing Guide. Relevant for patient portals, financial apps, and field operations apps.
Cloud Penetration Testing
Assesses AWS, Azure, Google Cloud, and multi-cloud controls — IAM misconfigurations, storage exposure, serverless vulnerabilities, container security, and cloud-native service misuse — with platform-specific shared-responsibility expertise.
OT and ICS Testing
Follows NIST SP 800-82 guidance, focusing on the IT/OT boundary, engineering workstation security, historian systems, and protocol-level vulnerabilities in SCADA and DCS environments — without disrupting production.
Social Engineering & Phishing
Evaluates the human element — whether employees recognize and report phishing, vishing, and physical access attempts. Increasingly required by compliance frameworks and essential context for why technical controls alone are insufficient.
Manufacturers, utilities, and any organization where cyber compromise can affect physical processes should review OT and ICS penetration testing for manufacturers.
Choosing the Right Engagement Type
| Situation | Recommended Engagement Type | Knowledge Level |
|---|---|---|
| First penetration test; compliance baseline | External + Internal Network | Gray-box |
| Annual PCI-DSS Requirement 11.4 | External + Internal Network + Application | Gray-box |
| CMMC 2.0 pre-assessment | Network + CMMC-scoped environment | Gray-box |
| New customer-facing web application | Web Application | Gray-box or White-box |
| Manufacturing / industrial environment | OT / ICS | Gray-box with safety constraints |
| Mature security program; test detection capability | Red Team Operation | Black-box |
| Pre-release application security review | Web Application or Code Review | White-box |
The red team vs. pen test comparison covers the distinction between full red team operations and scoped penetration testing in more detail, including the program maturity indicators that suggest when each is appropriate.
How Penetration Testing Types Connect to Continuous Security
Point-in-time penetration testing tells you where your environment was vulnerable on the day of the engagement. For regulated organizations, that finding set needs a continuous monitoring layer to remain operationally relevant. Armorstack’s managed detection and response capability monitors for exploitation attempts against the same attack vectors identified during testing and validates that remediated controls are functioning as expected.
For governance questions about which testing types belong in your security program and how findings should inform risk decisions, Armorstack’s VERITY risk advisory practice provides the strategic layer that connects testing methodology to security program investment decisions.
To scope the right engagement type for your environment and compliance obligations, speak with the SENTRY team or review the full penetration testing services overview.
Frequently Asked Questions
What is the difference between black-box and gray-box penetration testing?
Black-box penetration testing gives testers no prior knowledge of the target, simulating an external attacker with only publicly available information. Gray-box testing provides partial information — such as network diagrams or user credentials — simulating an attacker who has gained limited initial access. Gray-box is more efficient for compliance purposes; black-box provides more realistic external attack simulation.
What types of penetration testing do most compliance frameworks require?
PCI-DSS v4.0 Requirement 11.4 requires external and internal network penetration testing annually. HIPAA Security Rule technical evaluations are commonly satisfied by network and application penetration testing. CMMC 2.0 requires testing aligned to NIST SP 800-171 assessment objectives. Most frameworks accept gray-box methodology.
When should an organization choose OT/ICS penetration testing?
OT and ICS penetration testing is appropriate for manufacturers, utilities, and any organization where cyber compromise can affect physical processes. It follows NIST SP 800-82 guidance and focuses on the IT/OT boundary and industrial protocol security, using methodology designed to avoid disrupting production systems during testing.
Is a red team operation the same as a penetration test?
No. A penetration test maximizes vulnerability discovery within a defined scope. A red team operation simulates a full adversary campaign to test an organization’s detection and response capability — the security operations team is typically unaware of the operation. Red team engagements are appropriate for organizations with mature security programs that have already addressed most basic penetration test findings.
Ready to Scope the Right Engagement?
Talk to the SENTRY team about which penetration testing type — and which knowledge-level framework — matches your compliance requirements and security program maturity.