







Are denial-of-service attacks also tested?
Denial-of-Service (DoS) attacks are only examined with prior agreement from the respective client. Additionally, only specific types of Denial-of-Service attacks are considered during penetration tests. In particular, those that allow attackers to take down the system with minimal resource cost. This may be due to a misconfiguration or software flaw. These types of attacks are conducted after agreement to verify their feasibility.
However, attacks that completely saturate the client’s available network capacity are not tested. These attacks are always possible for attackers with the appropriate resources and could potentially overload third-party systems. Therefore, Distributed Denial-of-Service (DDoS) attacks are also not part of a penetration test.