Skip to content
Getting Digital

Cybersecurity

Penetration testing and ethical hacking

Penetration testing is the most romanticised corner of security and one of the most misunderstood. The job is not breaking in; it is breaking in with written permission, inside limits agreed in advance, and then telling a client in plain language what to fix first. Anyone drawn by the hacking should look hard at the scoping calls and the report writing, because that is where most of a working week goes.

Why this topic exists: Authorised attack as a profession: scoping, reconnaissance, exploitation, reporting (PTES; PenTest+ and CEH). Also the most-searched security topic on the course side.

A penetration test is an attack commissioned by the owner of a system, carried out by someone skilled enough to behave like a real adversary and disciplined enough to stay within what was agreed. The Penetration Testing Execution Standard, the most cited open description of the work, divides an engagement into seven phases. Only two of them are the exploitation people picture. The rest is conversation, research and writing, and the quality of an engagement is usually decided before any tool runs: a vague scope produces a vague report, however skilled the tester.

PhaseWhat the tester is doing
Pre-engagementAgreeing scope, rules, timing, contacts and written authorisation
Intelligence gatheringCollecting what can be learned about the target from outside
Threat modellingDeciding which assets matter and which attackers are plausible
Vulnerability analysisFinding weaknesses worth attempting
ExploitationShowing that a weakness can actually be used
Post-exploitationEstablishing what a foothold is worth to an attacker
ReportingExplaining findings, evidence and priorities to the owner

Vocabulary, and how the two main exams differ

A tester needs the defenders' vocabulary as much as the attackers'. Scoping language (black, grey and white box; in scope and out of scope), the gap between a vulnerability scan and a test, threat modelling, privilege escalation and lateral movement, and the CVSS ratings in which findings are expressed. A red team engagement is related but different: longer, driven by a goal, and also measuring whether the defenders notice. Two exams dominate the entry level of the field. PenTest+ covers the whole engagement and gives real weight to planning and reporting. The Certified Ethical Hacker credential is the name recruiters and public-sector lists request most, and it draws scepticism from practitioners who find it wide rather than deep. Both are largely written exams. Testers judge one another on practical assessments, so anyone aiming at consultancy work should plan for one of those as well.

Why strong hackers write weak tests

The commonest beginner mistake is believing the exploit is the product. Self-taught testers raised on capture-the-flag platforms are often technically sharp and still hand over reports a client cannot use: tool output pasted in bulk, every finding marked critical, no word about business impact. A client is paying for a ranked list of what to fix and why. The second mistake is legal. Practice labs teach that every machine in front of you is fair game; in paid work, touching a single host outside the agreed scope can end a career, and the exams probe that line harder than candidates expect.

Testing is rarely a first job. Most testers arrive from system administration, development or a SOC, because exploiting a system requires knowing how it is normally run. The adjacent topics are application security, where much modern testing happens, and vulnerability management, which is what the client does with your report after you leave. For an early check of aptitude, the free Cisco introduction to cybersecurity covers the ground underneath, and PenTest+ is the natural first exam once ordinary IT work has given you something to test against. Readers who want the defender's view of the same weaknesses should read vulnerability management next.

Next to this topic

Concepts to know

Glossary entries with the reason each one matters here.

Certifications that test it

Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.

Tools of the trade

Frequently asked

Is ethical hacking legal?
Only with authorisation. What separates a test from an offence is a written agreement from someone entitled to give it, naming the systems, the methods and the time window. Practising on your own machines or on dedicated training platforms is legal; probing a stranger's website out of curiosity is not, whatever your intentions.
PenTest+ or CEH first?
PenTest+ is the more rounded preparation for the job itself, with its emphasis on scoping and reporting. The CEH is worth having where an employer or contract names it explicitly. If neither requires it yet, spend the effort on hands-on skill and choose the exam when a job advert tells you which one it wants.
Can I become a penetration tester without IT experience?
Rarely directly. The testers who succeed understand networks, operating systems and applications as an administrator or developer would, and that usually takes a few years of ordinary IT work. Start there and build offensive skills in legal labs alongside it.
How is a vulnerability scan different from a penetration test?
A scan is automated and lists weaknesses that might exist. A test has a person try to use them, chain them together and show what an attacker could actually reach. Scans are cheap and frequent; tests are slower, periodic and answer a different question.

Courses in the directory

242 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.

Browse the directory shelf

Last reviewed 26 September 2026 · Getting Digital