GCSE · Computer Science · Edexcel · Spec 1CP2

Penetration testing

Some people break into computer systems for a living — and the organisation they break into asked them to.

Computer Science · Cyber security

White, grey or black box?

Read each tester's brief. How much has the tester been told about the system?

Everything, some of it, or nothing?

Still to sort

White box (0)

The tester has full knowledge of the system.

Where the line is: If anything important is held back, it is no longer white box — it is grey.

Grey box (0)

The tester has some knowledge, but not all.

Where the line is: Any real inside knowledge makes it grey; it is only black box when the tester knows nothing about the system.

Black box (0)

The tester has no knowledge of the system.

Where the line is: Knowing which organisation to target is not knowledge of its system — that is still black box.

6 of 6 still to sort.

A penetration tester is hired to attack a system — with the owner's permission — so its weaknesses can be found and fixed. Before the test, the organisation decides how much to tell them. Sort each brief, then switch the rule and sort it again by whose attack it imitates.

Watch out: The colour is only about how much the tester is told. White box is not the 'safe' test and black box is not the 'dangerous' one.

Who are penetration testers?

Same tools. So what's the difference?

Two people try to get into the same company's network using exactly the same tools and methods. One is a penetration tester. The other is a criminal.

What makes the penetration tester's attack acceptable? Pick the idea closest to what you think right now.
How sure are you?

The four stages

What happens first?

Put the four stages of a penetration test in the order they happen.

1 · First stage4 · Last stage
  1. Attack

    Try to gain access to the system or extract data, simulating real-world threats — while taking care not to damage the system.

  2. Reporting

    Write a clear report of the vulnerabilities found, how they were exploited, suggestions for fixing them and recommendations to improve security.

  3. Planning

    Define the objectives and scope, decide the rules and the type of test (white, grey or black box), and get permission.

  4. Discovery

    Collect as much data as possible about the system's structure, software and weaknesses — without being detected.

Watch out: Permission belongs in planning — before any data is collected and long before any attack.

Predict, then check

This is a simulated baiting test — one kind of social-engineering attack.

A tester leaves an appealing USB stick in a company's reception. Several members of staff pick it up and plug it into their work computers. What should the company conclude?

Put it into words

Physical, software or social engineering?

A tester's plan for a sports centre: • Tailgating — walk in close behind a member of staff as they badge through a locked door. • Shoulder surfing — stand behind the receptionist and watch them type a password. • Denial-of-service — flood the online booking system with requests. • SQL injection — type database commands into the booking website's login box instead of a username. • Blagging — phone the office pretending to be an IT technician and ask for a password.

Simulated attacks in a penetration test come in three families: physical, software and social engineering. From the tester's plan below, describe one test from each family and say what that test checks. [6 marks]

0 words · your answer stays on this page and is not sent anywhere.

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

A penetration test is a permitted, controlled attack — and its whole point is the fixes it leads to.

What you need to know

  • Penetration testing is a controlled, simulated cyber attack used to test the security of a system, network or application.
  • Its purpose is to find vulnerabilities so the organisation can fix them before attackers exploit them.
  • Ethical hackers use the same tools and methods as malicious hackers — the difference is permission, obtained before the test starts.
  • White box = full knowledge (malicious insider view); grey box = some knowledge (balanced view); black box = no knowledge (external hacker view).
  • A test runs planning → discovery → attack → reporting, and its simulated attacks can be physical, software or social engineering.

The big picture

Penetration testing is a controlled, simulated cyber attack on a computer system, network or application. Its purpose is to find security weaknesses (vulnerabilities) so they can be fixed before real attackers exploit them. It is carried out by ethical hackers, who use the same tools and methods as criminals but only with the owner's permission, obtained before the test begins. A test is white, grey or black box depending on how much the tester is told, and it runs through four stages: planning, discovery, attack and reporting.

Key points

1A penetration test is a simulated, controlled attack — real methods, used to test security, not to cause harm.
2Permission comes first: testing without it is illegal and unethical, however useful the findings.
3How much the tester is told sets the test type — and the type sets whose attack is being imitated.
4Planning, discovery, attack, reporting: the report of vulnerabilities and fixes is what makes the organisation safer.
5Testers check people and places as well as programs: physical security, staff training, data storage and software security.

Worked example

Problem

A bank wants to find out how well its online banking would hold up against a hacker on the internet who knows nothing about its system. Which type of penetration test should it choose? Explain your choice.

⚠ Watch out

Mixing up the viewpoints: a white box tester knows everything, so the test imitates a malicious insider — not an outside hacker. The outside hacker is black box, starting with nothing.

🧠

Memory hook

Think of the box as how much light gets in. A white box is see-through: the tester sees everything inside, like a member of staff. A black box is sealed: they see nothing, like a hacker on the outside. A grey box lets some light through.

✓

Check yourself

Why is it the reporting stage, not the attack itself, that actually makes an organisation's system safer?

Flashcards

(15)
What is penetration testing?
A controlled, simulated cyber attack used to test the security of a computer system, network or application.
Why do organisations pay for penetration testing?
To find security weaknesses (vulnerabilities) and fix them before real attackers can exploit them.
Who carries out penetration tests — and how are they different from criminal hackers?
Penetration testers, also called ethical hackers. They use the same tools and methods as malicious hackers, but they are authorised: the owner has given permission and knows the test is happening.
When must permission for a penetration test be obtained?
Before the simulated attack starts. Testing without permission is illegal and unethical.
White box test: what does the tester know, and whose attack does it imitate?
Full knowledge of the system, like a member of staff — so it tests the system from the perspective of a malicious insider.
Black box test: what does the tester know, and what does it show?
No knowledge of the system. It takes the view of an external hacker and shows how secure the system is from the outside, where most threats originate.
What does a grey box test combine?
An external attacker's perspective with some — but not all — internal knowledge of the system: a balanced view.
Why test a system from more than one perspective?
Different perspectives help identify different weaknesses and areas for improvement that could pose a security risk.
Name the four stages of a penetration test, in order.
Planning → discovery → attack → reporting.
What is decided in the planning stage?
The objectives and scope, the rules, the type of test (white, grey or black box) — and permission is obtained.
What does the tester do in the discovery stage?
Collects as much data as possible about the system's structure, software and weaknesses, without being detected.
In the attack stage, what must the tester take care not to do?
Damage the system. They try to gain access or extract data by simulating real-world threats, carefully.
What goes into a penetration test report?
The vulnerabilities found, how they were exploited, suggestions for fixing them and recommendations to improve security.
Give the three families of simulated attack, with an example of each.
Physical (tailgating, shoulder surfing); software (denial-of-service, SQL injection); social engineering (blagging, baiting).
Which four areas might a penetration tester check?
Physical security (locks, CCTV, badges, unattended unlocked computers), staff training, data storage and software security (patches, antivirus, firewalls).

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More Edexcel GCSE Computer Science topics

See the full Edexcel Computer Science curriculum →

How this lesson was checked. This Edexcel GCSE Computer Science (specification 1CP2)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 1 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.