← PenTest+: assessment, evidence, and remediation
03 / 6 · 40 MIN

Discovery, coverage, and validation

Combine techniques and validate findings before classifying them.

Concept and mechanism

Techniques observe different parts of a system. SAST analyzes code without requiring full application execution; DAST observes a runnable application; SCA examines components and dependencies. None automatically replaces the others or proves absence of business-logic flaws. A transitive library can appear in the lockfile without appearing in the direct list and needs version and usage analysis. For credentialed scans, confirm local checks actually ran. A complete target list does not guarantee complete coverage. Also distinguish component presence, vulnerability applicability, and exploitation demonstrated within authorized context.

Guided application

In the fictional exercise, fifteen of sixty hosts failed authentication. Credentialed coverage is forty-five of sixty, or seventy-five percent. Remaining hosts need completion rather than a “remediated” state. Elsewhere in the report, an old banner corresponds to a backported package. Link the advisory, installed release, and condition before reviewing the finding as a possible false positive. Retain evidence even when classification changes. When selecting NSE scripts, check behavior and scope: loading everything can include techniques beyond low-impact enumeration. For prioritization, record CVSS version and vector and add exposure and business context. The score communicates severity and assumptions; it does not directly convert into financial loss or guaranteed exploitation.

IN PRACTICE

45 of 60 hosts with successful local checks: 75% credentialed coverage.

Common pitfalls

Ignored indirect dependency; attempted scan as complete; banner as patched state; every script as low impact.

Related topics: Scope, communication, and evidence · Reconnaissance and result interpretation · Web and API flaws and remediation

Take this idea with you

Connect each conclusion to method, coverage, and evidence.

Create account

Reference: Security testing and assessment · PT0-003 / PenTest+ V3; objectives 3.0; launched 2024-12-17