CompTIA PenTest+ (PT0-003)Engagement ManagementMedium

A client requests a penetration test focused on their customer-facing web application, specifically wanting the assessment to cover categories such as injection flaws, broken authentication, and business logic vulnerabilities using a structured, widely recognized methodology. Which framework should the tester primarily reference to structure this assessment?

  1. AOSSTMM
  2. BOWASP Testing Guide
  3. CNIST SP 800-115
  4. DPTES
Show answer & explanation

Correct answer: B. OWASP Testing Guide

The OWASP Testing Guide is specifically designed for structuring web application security assessments, covering categories like injection, authentication, and business logic testing in detail.

Why the other options are wrong

  • A. OSSTMM is a broader operational security methodology, not web-app specific.
  • C. NIST SP 800-115 is a general technical security testing guide, less specific to web app categories.
  • D. PTES is a general penetration testing standard, not focused specifically on web app categories.

OWASP Testing Guide

A comprehensive framework for testing web application security, organized into categories like authentication, session management, and injection.

  • Maintained by OWASP community
  • Complements the OWASP Top 10
  • Provides detailed test cases per vulnerability category

Memory trick: OWASP = 'Only Web Apps' framework

More Engagement Management questions