CompTIA PenTest+ (PT0-003)Engagement ManagementMedium
A penetration testing team following PTES has completed intelligence gathering on a target organization. Before running vulnerability scans, the team categorizes potential threat agents, maps them to specific business assets, and derives plausible attack scenarios based on the attackers' likely capabilities and motivations. Which PTES phase does this activity represent?
- APost-Exploitation
- BThreat Modeling
- CVulnerability Analysis
- DExploitation
Show answer & explanationAnswer & explanation
Correct answer: B. Threat Modeling
The Threat Modeling phase of PTES uses intelligence gathered previously to identify threat communities, map them to organizational assets, and build realistic attack scenarios that guide subsequent testing. Vulnerability Analysis instead focuses on identifying technical weaknesses, while Exploitation and Post-Exploitation occur after threats and vulnerabilities have already been mapped.
Why the other options are wrong
- A. Occurs after a foothold is gained, far later in the methodology.
- C. Focuses on identifying and validating technical flaws, not on modeling attacker motivations.
- D. Involves actively attempting to breach systems, which happens after threat modeling.
PTES Threat Modeling
The PTES phase where testers identify threat communities, map them to business assets, and determine realistic attack scenarios before technical testing begins.
- Uses output from Intelligence Gathering
- Maps threat agents to specific assets
- Produces attack scenarios that guide Vulnerability Analysis and Exploitation
Memory trick: Pirates Intelligently Threaten Villagers, Exploiting, Plundering, Reporting