What are the types of penetration testing?
Pentests are named along two independent axes: what is being attacked, and what the tester is told before starting. A "gray-box external web application test" uses both. The target axis decides which weaknesses the test can reach; the knowledge axis decides how much of the budget goes on discovery versus attack.
By target, the common types are external network, internal network, web application, API, mobile application, cloud, wireless, social engineering and physical. By knowledge, they are black-box, gray-box and white-box, covered in detail in black-box, gray-box and white-box testing.
What does each type cover, and when do you need it?
Each type attacks a different surface and answers a different question.
| Type | What the tester attacks | Typical findings | You need it when |
|---|---|---|---|
| External network | Internet-facing hosts, VPN and remote access, mail, DNS, exposed admin panels | Unpatched services, default credentials, exposed management ports, forgotten hosts | You have any public IP space; PCI DSS 11.4.3 and FedRAMP both require it |
| Internal network | Workstations, servers, directory services and file shares from inside | Weak internal credentials, privilege escalation to domain admin, flat networks | You run a corporate network or on-premises systems; PCI DSS 11.4.2 requires it |
| Web application | A browser-based app, its login, sessions and every feature behind it | Broken access control, injection, XSS, CSRF, business logic flaws | You ship a web product or customer portal |
| API | REST, GraphQL or gRPC endpoints, usually from the spec | BOLA, broken function level authorization, mass assignment, SSRF | Your product exposes an API to customers, partners or your own apps |
| Mobile application | The iOS or Android app and the backend it calls | Insecure local storage, weak certificate handling, backend authorization flaws | You publish a mobile app; FedRAMP lists it as a mandatory vector |
| Cloud | Accounts, IAM, storage, serverless and managed services in AWS, Azure or GCP | Over-permissive roles, public buckets, metadata service abuse, cross-account trust | Your production runs in a public cloud |
| Wireless | Wi-Fi networks, guest isolation, rogue access points | Guest networks that reach internal systems, weak authentication, rogue APs | You have offices with Wi-Fi that touches internal systems |
| Social engineering | Staff, through phishing, phone pretexts or messaging | Credential capture, users running untrusted scripts, weak help desk verification | Staff hold privileged access; FedRAMP requires a phishing vector |
| Physical | Buildings, badge readers, server rooms, unattended ports | Tailgating, unlocked network ports, devices left unattended | You operate facilities that house sensitive systems |
Specialized variants sit inside these. A segmentation test is a network test that checks whether out-of-scope networks can reach the cardholder data environment. An LLM penetration test is an application test aimed at prompt injection and tool misuse in AI features.
How do network, application and API tests differ?
A network test attacks hosts and services; an application or API test attacks what the software does once you reach it. A network tester who finds port 443 open with current TLS moves on; an application tester logs in as two users and checks whether one can read the other's data.
API testing overlaps with web application testing but deserves its own line in the scope. APIs expose object IDs and functions directly, without a UI hiding them, and many endpoints exist only for mobile apps or integrations. The OWASP API Security Top 10 2023 puts broken object level authorization first. Finding it requires accounts for at least two users, which is why application and API tests are nearly always authenticated.
The PCI SSC's penetration testing guidance makes the same distinction in a compliance setting: both internal and external tests must include application-layer and network-layer assessments. A network-only test does not meet that.
What makes cloud testing different?
In the cloud, much of the attack surface is configuration and identity, and the provider sets rules on what you may test. Under the shared responsibility model you can test your own resources, not the provider's underlying infrastructure.
Provider policies differ and change, so read them before scoping. AWS, for example, permits testing of listed services without prior approval but prohibits denial of service, request flooding, and DNS zone walking against Route 53, among other activities. A cloud test typically combines an authenticated configuration review (IAM policies, storage permissions, logging) with attacks from the application inward, such as server-side request forgery against the instance metadata service.
When are social engineering and physical tests in scope?
Only when they are explicitly agreed, because they target people and places. NIST SP 800-115 treats both as part of penetration testing and advises that security guards be told how to verify a tester's authorization, such as a point of contact or documentation. Most application-focused tests exclude both in the rules of engagement.
FedRAMP is the notable framework that requires one. Its Penetration Test Guidance makes "External to Corporate" a mandatory attack vector: a phishing campaign against the cloud provider's system administrators and the staff who can influence them.
How do you choose which types to buy?
Start from where your sensitive data and privileged functions live, then add what your frameworks name. A practical sequence:
- List the surfaces. Public IP ranges, web apps, APIs, mobile apps, cloud accounts, office networks.
- Mark where the data is. The surfaces that store or reach customer data, secrets or payment flows get tested first.
- Add framework requirements. PCI DSS requires internal and external tests plus segmentation testing where segmentation reduces scope. FedRAMP names six mandatory attack vectors. See internal vs external penetration testing.
- Pick the knowledge level. Gray-box for most application and API work; black-box when the question is what an outsider can find.
- Write it into the scope. Name each type, target and exclusion so the report states exactly what was covered.
For a SaaS company with no offices of note, that usually means a gray-box web application and API test, a cloud configuration test, and an external network test of the public perimeter. For the process each test follows, see penetration testing methodology.
[ Sources ]
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment (sections 2.4 and 5.2)
- PCI SSC Information Supplement: Penetration Testing Guidance v1.1 (2017), section 2.2
- FedRAMP Penetration Test Guidance v3.0 (2022), section 3
- OWASP API Security Top 10 2023
- OWASP Mobile Application Security Testing Guide (MASTG)
- AWS: Penetration testing policy
Written by Parameter · Last reviewed

