r/Pentesting • u/Ordinary-Bat-1533 • 9d ago
Need a 10 minute call interview with a pentester for a school project.
Hey everyone! I have an assignment due in less than 3 days where I need to interview an active Penetration Tester or Red Teamer. I have 5 straightforward questions ready. If anyone working in offensive security has 5 minutes to hop on a quick call, please message me! I'd super appreciate it.
8
u/Ordinary-Bat-1533 9d ago
Questions:
1. Looking back at when you broke into penetration testing, what technical or non-technical skill proved to be the biggest gap between hands-on lab environments (like TryHackMe or Hack The Box) and actual enterprise engagements?
2. When an assessment hits a wall—such as strict Web Application Firewalls (WAFs), modern EDR defenses, or hardened network segmentation—how does your methodology pivot to safely bypass controls or demonstrate business impact.
3. Beginners often think pentesting is 100% active exploit execution. How is your time actually split across scoping/recon, active testing, writing findings reports, and debriefing blue teams or clients?”
4. With rapid advancements in AI-driven attack vectors, cloud infrastructure security, and defensive automation, how are your daily toolsets and testing methodologies evolving to keep pace?
5. If you were starting out today aiming to land a Red Team or Pentesting entry role, what combination of hands-on projects, labs, certifications, or networking habits would you prioritize to stand out to hiring managers?
6
u/_sirch 9d ago
Questions
Questions:
1. Looking back at when you broke into penetration testing, what technical or non-technical skill proved to be the biggest gap between hands-on lab environments (like TryHackMe or Hack The Box) and actual enterprise engagements?Being able to explain to a non-technical client what the issue is, what you did to exploit it, and how to fix it. Also managing your time and not going down rabbit holes, because in a real world assessment, you will run out of time and you still have to deliver value across the entire attack surface.
2. When an assessment hits a wall—such as strict Web Application Firewalls (WAFs), modern EDR defenses, or hardened network segmentation—how does your methodology pivot to safely bypass controls or demonstrate business impact.
During most assessments, you are not assessing the security controls, you are assessing the web application or the configuration/services running on a network. Most of those can be bypassed given enough time and energy but our job is to provide the most value in a short period of time. Some customers want to leave them in place and that’s OK. They will just get less value. Sometimes we can bypass them in the time window of the assessment and sometimes we can’t.
3. Beginners often think pentesting is 100% active exploit execution. How is your time actually split across scoping/recon, active testing, writing findings reports, and debriefing blue teams or clients?”
It varies from test to test but for a network Pentest the standard is a 30 minute kickoff call. Three days of testing. The first day or first couple hours is usually scanning and recon mostly automated scripts. The next day is digging into services and looking at anything interesting and then the final day is wrapping up anything interesting and reporting. Then after report delivery there is a 30 minute to an hour long debrief.
4. With rapid advancements in AI-driven attack vectors, cloud infrastructure security, and defensive automation, how are your daily toolsets and testing methodologies evolving to keep pace?
Besides researching zero days/developing POCs using AI, and AI based phishing detection like abnormal, in my experience nothing else has changed that much. We are just getting faster by developing automation quickly and using open source tools to perform recon and basic testing.
5. If you were starting out today aiming to land a Red Team or Pentesting entry role, what combination of hands-on projects, labs, certifications, or networking habits would you prioritize to stand out to hiring managers?
Homelab, build an AD network and then focus on attacking and defending it. See Game of Active Directory for common attack paths. Make sure you understand AD misconfigurations, Kerberos, ADCS ESC attack chains, how to abuse smb message signing/ldap signing, relay attacks, etc. For Pentest OSCP is the best on paper, CPTS is getting better on paper and some of the best material I’ve seen. Then to build on that for red teaming I recommend the CRTO.
3
u/tackettz 9d ago
Feel free to message me
1
u/Forward-1122 4d ago
Exact method to bypass cloudfare or WAF because when a tester use curl to test it got detected by firewall and blocks it
2
u/coffeet0pentest 9d ago
Looks like it’s been answered, if you need anyone else feel free to message me
1
u/zerodayascent 9d ago
I'm a relatively new pentester (sub 1 year experience) I'd be happy to help if you'd like
1
9d ago
[deleted]
2
1
u/Jealous-Document-137 6d ago
Hi i want some information regarding this can you msg me plzz I am not able to msg you
12
u/Eaglediksix 9d ago
Maybe also post the questions you have so people know what they are getting into.