Types of Penetration Testing: Choosing the Right Engagement for Your Risk Profile

SENTRY — Penetration Testing

Types of Penetration Testing: Choosing the Right Engagement for Your Risk Profile

Penetration testing is not a single service — it is a category of security assessments with distinct methodologies, scopes, and objectives. Understanding the types available helps regulated organizations select the engagement that matches their compliance requirements, threat model, and security program maturity.

Knowledge-Level Frameworks

Every Engagement Starts With a Knowledge-Level Decision

Every penetration test operates within one of three knowledge-level frameworks that define how much information testers have about the target environment before the engagement begins. The choice affects the realism of the simulation, the efficiency of the engagement, and what the findings tell you about your defensive posture.

Black-Box Testing

Testers begin with no prior knowledge of the target — only what an external attacker could gather through open-source intelligence and active reconnaissance. This format most accurately simulates an opportunistic external attacker and is best suited for organizations validating mature perimeter controls under realistic conditions.

Gray-Box Testing

Testers receive partial information — network diagrams, application documentation, or user-level credentials — simulating an attacker who has gained an initial foothold. Gray-box is the most common format for compliance-driven testing, including PCI-DSS Requirement 11.4 and CMMC-aligned assessments.

White-Box Testing

Testers get full access to source code, architecture documentation, configurations, and administrative credentials. Not designed to simulate an attacker — designed to find every vulnerability with maximum efficiency. Best for pre-release application reviews, code audits, and configuration reviews where completeness matters most.

See how this applies to defense-contractor compliance in penetration testing for CMMC.

By Target Environment

Penetration Testing by Target Environment

Beyond knowledge level, penetration tests are categorized by the environment or asset type they target. Each category requires different expertise, tools, and methodology.

Network Penetration Testing

Assesses firewalls, routers, switches, VPNs, and wireless infrastructure. External testing covers internet-facing systems; internal testing evaluates lateral movement, Active Directory weaknesses, and segmentation failures. The baseline engagement for most compliance programs.

Web Application Testing

Targets injection flaws, authentication weaknesses, authorization failures, business logic errors, and cryptographic issues, following the OWASP Testing Guide. Required for any organization with internet-facing applications handling sensitive data.

Mobile Application Testing

Evaluates iOS and Android client-side storage, inter-process communication, API security, and authentication under the OWASP Mobile Security Testing Guide. Relevant for patient portals, financial apps, and field operations apps.

Cloud Penetration Testing

Assesses AWS, Azure, Google Cloud, and multi-cloud controls — IAM misconfigurations, storage exposure, serverless vulnerabilities, container security, and cloud-native service misuse — with platform-specific shared-responsibility expertise.

OT and ICS Testing

Follows NIST SP 800-82 guidance, focusing on the IT/OT boundary, engineering workstation security, historian systems, and protocol-level vulnerabilities in SCADA and DCS environments — without disrupting production.

Social Engineering & Phishing

Evaluates the human element — whether employees recognize and report phishing, vishing, and physical access attempts. Increasingly required by compliance frameworks and essential context for why technical controls alone are insufficient.

Manufacturers, utilities, and any organization where cyber compromise can affect physical processes should review OT and ICS penetration testing for manufacturers.

Engagement Selection

Choosing the Right Engagement Type

SituationRecommended Engagement TypeKnowledge Level
First penetration test; compliance baselineExternal + Internal NetworkGray-box
Annual PCI-DSS Requirement 11.4External + Internal Network + ApplicationGray-box
CMMC 2.0 pre-assessmentNetwork + CMMC-scoped environmentGray-box
New customer-facing web applicationWeb ApplicationGray-box or White-box
Manufacturing / industrial environmentOT / ICSGray-box with safety constraints
Mature security program; test detection capabilityRed Team OperationBlack-box
Pre-release application security reviewWeb Application or Code ReviewWhite-box

The red team vs. pen test comparison covers the distinction between full red team operations and scoped penetration testing in more detail, including the program maturity indicators that suggest when each is appropriate.

Beyond the Point-in-Time Test

How Penetration Testing Types Connect to Continuous Security

Point-in-time penetration testing tells you where your environment was vulnerable on the day of the engagement. For regulated organizations, that finding set needs a continuous monitoring layer to remain operationally relevant. Armorstack’s managed detection and response capability monitors for exploitation attempts against the same attack vectors identified during testing and validates that remediated controls are functioning as expected.

For governance questions about which testing types belong in your security program and how findings should inform risk decisions, Armorstack’s VERITY risk advisory practice provides the strategic layer that connects testing methodology to security program investment decisions.

To scope the right engagement type for your environment and compliance obligations, speak with the SENTRY team or review the full penetration testing services overview.

FAQ

Frequently Asked Questions

What is the difference between black-box and gray-box penetration testing?

Black-box penetration testing gives testers no prior knowledge of the target, simulating an external attacker with only publicly available information. Gray-box testing provides partial information — such as network diagrams or user credentials — simulating an attacker who has gained limited initial access. Gray-box is more efficient for compliance purposes; black-box provides more realistic external attack simulation.

What types of penetration testing do most compliance frameworks require?

PCI-DSS v4.0 Requirement 11.4 requires external and internal network penetration testing annually. HIPAA Security Rule technical evaluations are commonly satisfied by network and application penetration testing. CMMC 2.0 requires testing aligned to NIST SP 800-171 assessment objectives. Most frameworks accept gray-box methodology.

When should an organization choose OT/ICS penetration testing?

OT and ICS penetration testing is appropriate for manufacturers, utilities, and any organization where cyber compromise can affect physical processes. It follows NIST SP 800-82 guidance and focuses on the IT/OT boundary and industrial protocol security, using methodology designed to avoid disrupting production systems during testing.

Is a red team operation the same as a penetration test?

No. A penetration test maximizes vulnerability discovery within a defined scope. A red team operation simulates a full adversary campaign to test an organization’s detection and response capability — the security operations team is typically unaware of the operation. Red team engagements are appropriate for organizations with mature security programs that have already addressed most basic penetration test findings.

Ready to Scope the Right Engagement?

Talk to the SENTRY team about which penetration testing type — and which knowledge-level framework — matches your compliance requirements and security program maturity.