Which penetration test should you choose?
Compare web, external and internal penetration testing to choose the right engagement for the scope and objective.
Short answer
Choose web penetration testing for an application or API, external penetration testing for the Internet-facing attack surface, and internal penetration testing to measure compromise paths from inside the corporate network. The three approaches are complementary but answer different questions.
The right choice for your need
A business application, customer portal or API calls for web testing. Domains, IP addresses, VPNs, published services and administration interfaces call for external testing. Concerns about internal pivoting, shares, workstations, Wi-Fi or Active Directory call for internal testing.
Next step
When the scope is unclear, a scoping discussion identifies critical assets, production constraints and the most useful engagement. The expected output should remain actionable: evidence, priorities and a remediation plan.