Penetration Testing
Penetration Testing activity goes a step further and exploits the vulnerabilities identified in the Vulnerability Assessment stage. This activity is similar to the way a hacker would exploit the system and gain an access to sensitive system resources, information without any authorization from the relevant authorities.
The vulnerabilities identified in the VA exercise are researched upon and exploited using open source and commercially available tools. The outcome of this exercise enables an organization to view the depth of resources and information available in case an actual penetration occurs.