Penetration Testing & Firewalls – Quick-Review Notes

Phishing Identification

  • Fraudulent email indicator

  • Warning signs:

    • Altered/unfamiliar sender address

    • Poor grammar/spelling

    • Urgent requests for action

    • Suspicious hyperlinks

    • Vague security wording

General Network-Security Countermeasures

  • extFirewallsext{Firewalls}

  • extAnti−malwaresoftwareext{Anti-malware software}

  • extEncryptionext{Encryption}

  • Strong passwords & usernames

  • User-access levels

  • Penetration testing (pen testing)

Penetration Testing (Pen Testing)

  • Authorised simulation of cyber-attacks to expose vulnerabilities by ethical hackers.

  • Goal: gain unauthorised access, extract data.

Five-Step Pen-Testing Cycle
  • 11 Find vulnerability

  • 22 Design attack scenario

  • 33 Assign ethical-hacker team

  • 44 Identify data that could be stolen

  • 55 Report & act on findings

Internal vs. External Tests
  • External: assesses entry points & post-breach reach from an outsider's view.

  • Internal: gauges damage from insider threat (tester has employee access).

Threats Limited / Prevented
  • extSQL−injectionext{SQL-injection}

  • Data interception & theft

  • Other exploits discovered

Firewalls

  • Barrier between internal network and external traffic (e.g., Internet).

  • Implemented via hardware, software, or both.

  • Operates by inspecting data packets and applying security rules.

Protection Capabilities
  • Blocks malware-laden packets.

  • Thwarts brute-force log-in attempts.

  • Filters phishing traffic.

Combined Security Benefits

  • Pen testing proactively finds vulnerabilities; Firewalls provide real-time filtering.

  • Together, they reduce attack surface and mitigate common threats like malware, brute-force attacks, phishing, extSQL−injectionext{SQL-injection}, and data theft.