The All-in-One IT Management Software That Replaces 10 Tools — VAPT Built In.

One platform for server monitoring, IT assets, helpdesk & vulnerability assessment and penetration testing (VAPT) — tenant-isolated, audit-ready, live in under 30 minutes.

New · Release 2026.04 — Multi-tenant audit exports & SLA dashboards now live See changelog →
Security & Compliance

Types of Penetration Testing: A Complete Guide (2026)

Every type of penetration test explained — network, web, mobile, API, cloud, wireless and social engineering — plus black, grey and white box methods and when to use each.

Written by the Infronest Security Research Team — certified professionals (CEH, OSCP, GPEN) with 10+ years of hands-on delivery. Reviewed against PTES, NIST SP 800-115 and the OWASP Testing Guide v4.2.

ShareLinkedInX

'Penetration testing' is not one service. Asking a provider for 'a pen test' without specifying the type is how organisations end up paying for a scan of their website when their real risk was in Active Directory. Here is the full map.

By target

Types of penetration testing by what is tested

  • Network penetration testing — routers, firewalls, servers, Active Directory. Split into external (from the internet) and internal (from inside the perimeter).
  • Web application penetration testing — authentication, session management, injection, access control and business logic in web apps.
  • Mobile application penetration testing — Android and iOS apps, their local storage, and the APIs behind them.
  • API penetration testing — authentication, authorisation (BOLA/BFLA), rate limiting and data exposure in REST and GraphQL APIs.
  • Cloud penetration testing — IAM policies, storage permissions, security groups and misconfigurations in AWS, Azure or GCP.
  • Wireless penetration testing — Wi-Fi encryption, rogue access points, guest network isolation.
  • Social engineering — phishing simulations, pretexting and physical access attempts targeting people rather than systems.
  • Physical penetration testing — tailgating, badge cloning and access to server rooms.

External vs internal testing

External testing simulates an attacker on the internet with no prior access; it validates your perimeter. Internal testing assumes an attacker already has a foothold — a phished employee, a compromised contractor — and measures how far they could move. Most compliance frameworks, including PCI DSS Requirement 11.4, require both scopes.

By method

Black box, grey box and white box

  • Black box — the tester gets no prior knowledge, exactly like an outside attacker. Most realistic, but time is spent on discovery rather than depth.
  • Grey box — the tester gets limited knowledge, typically user-level credentials. Simulates a compromised employee and is the most common engagement type because it balances realism and coverage.
  • White box — the tester gets full architecture, credentials and sometimes source code. Maximum coverage per rupee spent; ideal before a product launch.

Which type do you actually need?

  • You have internet-facing servers and have never tested — start with external network testing.
  • You just launched or majorly changed a web app — web application testing, grey box.
  • You handle payments — PCI DSS requires both internal and external network testing annually, plus quarterly scans.
  • You had a phishing incident — internal network testing, to see how far that foothold could have gone.
  • You are cloud-native with no on-prem estate — cloud configuration plus API testing beats classic network testing.
  • You built a mobile app — mobile application testing, and make sure the APIs behind it are in scope too.

What each type typically costs

  • External network — USD 3,000 to 15,000 for a small to mid-size scope
  • Internal network — USD 8,000 to 30,000 depending on Active Directory complexity
  • Web application — USD 5,000 to 25,000 for a medium-complexity application
  • Mobile application — USD 5,000 to 20,000 per platform, including the API layer
  • Cloud configuration — varies widely with account and workload count
  • Social engineering — often priced per campaign and per head count

Infronest

Conclusion

Whichever types you commission, the operational load is the same: scoping documents, findings, CVSS scores, evidence, reports and retests — multiplied by every engagement and every client. Infronest's Security and VAPT module keeps all of it in one tenant-isolated workspace with audit-ready reporting.

Start a 14-day free trial at infronest.com — no credit card required.

Frequently Asked Questions

What are the main types of penetration testing?
By target: network (external and internal), web application, mobile application, API, cloud, wireless, social engineering and physical. By method: black box (no knowledge), grey box (limited knowledge) and white box (full knowledge).
Which type of penetration test is most common?
Grey-box web application testing and external network testing are the two most commonly commissioned, because web apps are the most exploited attack surface and the external perimeter is what any internet attacker reaches first.
How many types of penetration testing do I need?
Test what you actually run. A SaaS company usually needs web application, API and cloud testing. A company with on-premise infrastructure needs external and internal network testing. Compliance frameworks such as PCI DSS specify the minimum scopes you must cover.

About the Author

Infronest

Infronest Security Research Team

Certified security professionals (CEH, OSCP, GPEN, ISO 27001 Lead Auditor) with 10+ years of hands-on delivery. Content reviewed against PTES, NIST SP 800-115 and the OWASP Testing Guide v4.2.

Ready to unify your IT operations?

Start a 14-day free trial or book a demo — explore monitoring, assets, tickets, and security in one tenant-isolated workspace.