Penetration Testing: Courses to Train Your Team

Penetration testing is a businesses’ best defense against modern cybercrime. Follow these steps to teach your team how to do it.

Illustration representing penetration testing tips

Cyberattacks by hackers continue to grow more frequent, sophisticated, and damaging. Attack methodologies evolve so quickly that it’s nearly impossible to keep any single software or security measure impenetrable for long.

 

Luckily, the “black hat” hackers intent on breaking into systems to steal data aren’t the only experts who have access to these evolving techniques. 

 

As cybercrime has grown more advanced, the movement and profession of “ethical hacking” developed as a countermeasure. Ethical hackers help protect businesses from cyberattacks by conducting penetration tests. 

 

This is everything you need to know about penetration testing, including how you can train your team to test effectively.

 

 

Explore topics:

What is penetration testing?

In her course Cybersecurity Careers: Become a Penetration Tester, penetration tester and security consultant Tennisha Martin starts by providing the National Institute of Standards and Technology definition of penetration testing:

Icon what penetration testing is
Professional headshot of Tennisha Martin

Tennisha Martin
Executive Director and Chairwoman at BlackGirlsHack

Quote icon

“Pen testing, short for penetration testing, is defined by the National Institute of Standards and Technology as a method of testing where testers target individual components or the application as a whole to determine whether or not vulnerabilities can be exploited to compromise the application, its data, or its environmental resources.”

Why is penetration testing so important?

The number of cybersecurity attacks has skyrocketed in the past decade, and these attacks have grown significantly more sophisticated. It is estimated that cybercrime will cost businesses $8 trillion annually by 2023.

 

Unfortunately, cybercrime remains such a substantial threat because it continues to evolve at such a quick pace. Skilled hackers uncover new exploits they can use to compromise systems constantly, often rendering the most recent security software updates obsolete.

 

The most effective way to deter cyberattacks in this environment, therefore, is to employ ethical hackers to attempt to break into systems themselves, using the same tools and techniques as cybercriminals. By conducting regular penetration tests, businesses can continuously optimize their cybersecurity and stay one step ahead of possible attacks.

Icon representing the importance of penetration testing
Illustration representing importance of penetration testing
Quote icon

“No matter how diligent any of us are, an attacker may be able to breach the network defenses and compromise our systems. If you oversee protecting digital assets, the only way you'll know how your system will perform under attack is by testing your defenses.”

Penetration test steps

As Martin explains, the steps of a penetration test vary based on the scope, goals, and restrictions of the specific test in question, but the process itself generally follows four broad steps:

Icon representing penetration test steps

Planning

  • Set the scope: Define the scope of the penetration, including what systems the team will target and the specific goals of the penetration test.

     

  • Define rules of engagement: Set rules of engagement with the system owner, including the level of access the team will have and any testing constraints necessary.

     

  • Gather information: Perform initial information gathering on the target environment.

     

  • Obtain signed permission to conduct the test: Obtain written permission from the client to perform the penetration test.

Illustration representing planning
Professional headshot of Tennisha Martin

Tennisha Martin
Executive Director and Chairwoman at BlackGirlsHack

Quote icon

“In the planning phase, the rules of engagement are identified, the goals are set, and management approval is finalized.”

Discovery

Scanning

  • Conduct initial recon: Collect information about the target organization and system.

  • Perform a network scan: Scan the target network to identify live systems, open ports, and actively running services.

Enumeration

  • Review scan: Gather more detailed information on the services and applications discovered during scanning.

  • Review organizational information: Enumerate users, shares, and other resources connected to the network.

Vulnerability analysis

  • Access vulnerability: Identify and assess vulnerabilities identified during the scanning and enumeration processes.
  • Create a plan of attack: Assemble a list of potential vulnerabilities to attack.

  • Prioritize highest-level threats: Prioritize your list of vulnerabilities based on the viability and impact of their exploitability.

Illustration representing discovery
Professional headshot of Tennisha Martin

Tennisha Martin
Executive Director and Chairwoman at BlackGirlsHack

Quote icon

“Discovery typically involves two parts: scanning and enumeration, and vulnerability analysis.”

Attacking

  • Exploit vulnerabilities: Attempt to exploit the vulnerabilities identified during the discovery stage to gain unauthorized access to the target system.

     

  • Test the effect of successful exploits: Test any exploits successfully uncovered to ensure they compromise the target system. Compromises could allow you to raise your level of system access, build back doors into the data for future use, or even give you access to sensitive data.

     

  • Document findings: Take very detailed notes of every step you take during the pen test, including what vulnerabilities you uncover and exploit, how you found them, and the effect these exploits could have.

Illustration representing attacking
Professional headshot of Tennisha Martin

Tennisha Martin
Executive Director and Chairwoman at BlackGirlsHack

Quote icon

"Executing an attack requires a pen tester to attempt to exploit vulnerabilities of interest. The goal here is that you want to demonstrate to an organization what an attacker would be able to accomplish, given the company’s current state of their security. You have to understand your why, and also the business impact."

Reporting

  • Compile your findings: Summarize your findings into a client-facing report that shares the information you uncovered and how you found it on terms the client can understand.

     

  • Make remediation recommendations: Schedule a separate meeting with the client’s IT team to make comprehensive recommendations for correcting the exploits you uncovered during the pen test, to ensure they can’t be used again.
Illustration representing reporting
Quote icon

"After all testing is complete, the lead analyst compiles the results of the test. The report should be succinct and present only the findings and analysis. It should not contain pages of reports generated by a scanner. However, the team should be prepared to go over any details of the results. The report generally includes an executive summary."

Learn the skills you need to follow penetration testing steps today

Penetration testing requires a highly-advanced skill set, but building that skill set isn’t an insurmountable obstacle for your IT team. LinkedIn Learning offers several expert-taught learning paths specifically designed to help IT professionals develop the skills they’ll need to become certified penetration testers.

 

To start learning penetration testing skills today, start with the Become a Penetration Tester Learning Path on LinkedIn Learning.

Icon representing the importance of penetration testing
Illustration representing learning penetration testing skills
Contact sales now

An experienced sales specialist is here to help find the best solution for you.

An experienced sales specialist is here to help find the best solution for you.