GCSE · Computer Science · Edexcel · Spec 1CP2
Penetration testing
Some people break into computer systems for a living — and the organisation they break into asked them to.
Computer Science · Cyber security
White, grey or black box?
Read each tester's brief. How much has the tester been told about the system?
Everything, some of it, or nothing?
Still to sort
White box (0)
The tester has full knowledge of the system.
Where the line is: If anything important is held back, it is no longer white box — it is grey.
Grey box (0)
The tester has some knowledge, but not all.
Where the line is: Any real inside knowledge makes it grey; it is only black box when the tester knows nothing about the system.
Black box (0)
The tester has no knowledge of the system.
Where the line is: Knowing which organisation to target is not knowledge of its system — that is still black box.
A penetration tester is hired to attack a system — with the owner's permission — so its weaknesses can be found and fixed. Before the test, the organisation decides how much to tell them. Sort each brief, then switch the rule and sort it again by whose attack it imitates.
Predict, then check
This is a simulated baiting test — one kind of social-engineering attack.
A tester leaves an appealing USB stick in a company's reception. Several members of staff pick it up and plug it into their work computers. What should the company conclude?
WHAT YOU'VE LEARNED
A quick recap of today's lesson.
A penetration test is a permitted, controlled attack — and its whole point is the fixes it leads to.
What you need to know
- Penetration testing is a controlled, simulated cyber attack used to test the security of a system, network or application.
- Its purpose is to find vulnerabilities so the organisation can fix them before attackers exploit them.
- Ethical hackers use the same tools and methods as malicious hackers — the difference is permission, obtained before the test starts.
- White box = full knowledge (malicious insider view); grey box = some knowledge (balanced view); black box = no knowledge (external hacker view).
- A test runs planning → discovery → attack → reporting, and its simulated attacks can be physical, software or social engineering.
The big picture
Penetration testing is a controlled, simulated cyber attack on a computer system, network or application. Its purpose is to find security weaknesses (vulnerabilities) so they can be fixed before real attackers exploit them. It is carried out by ethical hackers, who use the same tools and methods as criminals but only with the owner's permission, obtained before the test begins. A test is white, grey or black box depending on how much the tester is told, and it runs through four stages: planning, discovery, attack and reporting.
Key points
Worked example
Problem
A bank wants to find out how well its online banking would hold up against a hacker on the internet who knows nothing about its system. Which type of penetration test should it choose? Explain your choice.
⚠ Watch out
Mixing up the viewpoints: a white box tester knows everything, so the test imitates a malicious insider — not an outside hacker. The outside hacker is black box, starting with nothing.
Memory hook
Think of the box as how much light gets in. A white box is see-through: the tester sees everything inside, like a member of staff. A black box is sealed: they see nothing, like a hacker on the outside. A grey box lets some light through.
Check yourself
Why is it the reporting stage, not the attack itself, that actually makes an organisation's system safer?
Flashcards
(15)What is penetration testing?
Why do organisations pay for penetration testing?
Who carries out penetration tests — and how are they different from criminal hackers?
When must permission for a penetration test be obtained?
White box test: what does the tester know, and whose attack does it imitate?
Black box test: what does the tester know, and what does it show?
What does a grey box test combine?
Why test a system from more than one perspective?
Name the four stages of a penetration test, in order.
What is decided in the planning stage?
What does the tester do in the discovery stage?
In the attack stage, what must the tester take care not to do?
What goes into a penetration test report?
Give the three families of simulated attack, with an example of each.
Which four areas might a penetration tester check?
Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.
Learning with Lightbulb is opening soon
You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.
Keep me postedMore Edexcel GCSE Computer Science topics
How this lesson was checked. This Edexcel GCSE Computer Science (specification 1CP2)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 1 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.