官术网_书友最值得收藏!

Status meeting and reports

Communication is key for a successful penetration test. Regular meetings should be scheduled between the testing team and the client organization and routine status reports issued by the testing team. The testing team should present how far they have reached and what vulnerabilities have been found up to that point. The client organization should also confirm whether their detection systems have triggered any alerts resulting from the penetration attempt. If a web server is being tested and a WAF was deployed, it should have logged and blocked attack attempts. As a best practice, the testing team should also document the time when the test was conducted. This will help the security team in correlating the logs with the penetration tests.

WAFs work by analyzing the HTTP/HTTPS traffic between clients and servers, and they are capable of detecting and blocking the most common attacks on web applications.
主站蜘蛛池模板: 徐州市| 湘乡市| 齐河县| 上蔡县| 万年县| 西青区| 贵南县| 临湘市| 云浮市| 靖安县| 柏乡县| 新龙县| 吴川市| 内黄县| 尼勒克县| 日土县| 襄樊市| 石河子市| 吉安市| 辰溪县| 乌审旗| 秀山| 内乡县| 股票| 洪泽县| 焦作市| 长垣县| 舞阳县| 马尔康县| 黄大仙区| 万全县| 绥宁县| 大洼县| 巴彦县| 驻马店市| 元阳县| 安岳县| 容城县| 育儿| 青神县| 雷山县|