GCSE · Computer Science · AQA · Spec 8525

Penetration testing

Imagine your school asks someone to break in at night. Not to steal anything: to find the unlocked window before a real burglar does. That's penetration testing, for computer systems.

Cyber security · Penetration testing

Who is the tester pretending to be?

Read each test brief. Is the tester starting like someone already inside, or like a stranger on the outside? Pick a brief, then put it where it belongs.

Still to sort

Simulates a malicious insider (0)

The tester starts with knowledge of the target system and possibly basic credentials.

Where the line is: Holding any credentials at all rules out the other type, which starts with no knowledge of any credentials.

Simulates an external attack (0)

The tester starts with no knowledge of any credentials for the target system.

Where the line is: Skill and tools don't decide the type. What the tester is given at the start does.

6 of 6 still to sort.

Each brief is an invented example. In every one, the organisation has asked for the test on its own system. The only thing that changes is how much it tells the tester first.

What is it for?

?

Reason it through

Why would an organisation ask someone to break into its own systems?

Link 1 of 4

First link · your turn

First, what does the tester actually do?

2
Locked — reveal the link above first
3
Locked — reveal the link above first
4
Locked — reveal the link above first

Spot the snag

Does a login spoil the test?

A tester is handed a basic staff login before they start. A classmate says: "Hang on. Penetration testing means getting in without usernames and passwords. So this can't be a real penetration test."

Which is closest to what you think right now?
How sure are you?

Put it in writing

Now explain it yourself

Explain what penetration testing is and what it is used for, and describe the two types of penetration testing. [6 marks]

0 words · your answer stays on this page and is not sent anywhere.

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

Two types of test, one question to ask: who is the tester pretending to be?

What you need to know

  • Penetration testing is the process of attempting to gain access to resources without knowledge of usernames, passwords and other normal means of access.
  • It is used to find security weaknesses so they can be fixed before a real attacker uses them.
  • First type: the tester has knowledge of, and possibly basic credentials for, the target system. This simulates an attack from inside the system (a malicious insider).
  • Second type: the tester has no knowledge of any credentials for the target system. This simulates an attack from outside the system (an external attack).

The big picture

Penetration testing means deliberately trying to get into a system the way an attacker would, so the weaknesses can be found and fixed. There are two types, and what separates them is what the tester is given at the start: knowledge and possibly basic credentials to act like a malicious insider, or no knowledge of any credentials to act like an external attacker.

Key points

1A penetration test is an attack the organisation asks for, aimed at its own systems.
2Every way in the tester finds is one a real attacker could have used, so it gets reported and fixed.
3The two types are told apart by the starting point: what the tester knows and which credentials they hold.
4Giving a tester basic credentials doesn't stop it being a penetration test. It's how the test acts like a malicious insider.
5When you describe a type, give both halves: what the tester starts with, and which attack it simulates.

Worked example

Problem

A company is worried that someone who works for it could misuse the access they already have. It wants a penetration test to find out what such a person could do. Which type of penetration test should it ask for, and what should the tester be given at the start?

⚠ Watch out

Deciding the type by how skilled the tester is or how clever their tools are. Skill doesn't decide it. What the tester knows and which credentials they hold at the start does.

🧠

Memory hook

Same break-in, different briefing. Handed a key (credentials) and a map (knowledge)? You're playing the insider. Handed nothing? You're playing the outsider.

✓

Check yourself

Close the page and say it out loud: what penetration testing is, what it's for, and the one thing that decides which type a test is.

Flashcards

(6)
What is penetration testing?
The process of attempting to gain access to resources without knowledge of usernames, passwords and other normal means of access.
What is penetration testing used for?
Finding weaknesses in a system so they can be fixed before a real attacker uses them.
A test starts with knowledge of the system and possibly basic credentials. Who is the tester playing?
A malicious insider: the test simulates an attack from inside the system.
A test starts with no knowledge of any credentials. Who is the tester playing?
An outsider: the test simulates an external attack, from outside the system.
A tester is handed one basic login and nothing else. Which attack does the test simulate?
An attack from inside the system (a malicious insider), because the tester holds credentials.
Is an 'external' penetration test done without the organisation's agreement?
No. Both types are tests the organisation asks for. 'External' names the attack being simulated.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 28 September 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.