What Does a Penetration Tester Do? Methodology, Tools,
Work Skills Corrected & verified

What Does a Penetration Tester Do? Methodology, Tools,

Published by When Notes Fly · View original ↗

Penetration tester job explained: 5-phase methodology, tool list per phase, types of pen tests compared, OSCP vs CEH vs PNPT, salary by certification level,...

What has been corrected on this page?

Every accepted correction to this page is recorded with the exact change, so readers can see how the page improved over time.

  1. 31 July 2026 · corrected by Emir Baycan

    This article on penetration testing careers was largely accurate technical and professional content, with one statistic needing correction: a HackerOne bug bounty earnings figure was attributed to the wrong report year and did not match the real published numbers.

    What the page claimed

    The article attributed a '27 percent earning $50,000, 5 percent earning $350,000' statistic to HackerOne's 2023 Hacker Report, figures that could not be verified in any HackerOne publication.

    What was corrected

    The article now cites HackerOne's real 2020 Hacker Report figures: 1.1 percent of hackers earning more than $350,000 annually, 3 percent earning more than $100,000, and 12 percent earning more than $20,000.

    Why: A web search for the specific '27 percent/$50,000' and '5 percent/$350,000' figures found no matching HackerOne publication, while the real, well-documented 2020 Hacker Report figures were confirmed across multiple sources including HackerOne's own press materials.

    View the full record →
  2. 12 July 2026 · corrected by Emir Baycan

    Verizon 2023 DBIR 74% figure is the human element, not patchable-vulnerability exploitation

    Before

    found that 74% of breaches involved exploiting known, patchable vulnerabilities, the same class of issues that automated scanners find.

    After

    found that 74% of breaches included the human element, errors, privilege misuse, social engineering, and stolen credentials, while exploitation of known, patchable vulnerabilities remains a common breach vector that automated scanners find.

    Why: Verified fix already fully applied in article body. No secondary leftovers found in FAQ.

    View the full record →

Who checked this page?

1 contributor has checked "What Does a Penetration Tester Do? Methodology, Tools," on When Notes Fly. Each name below links to that person's public CitePep profile, where every contribution they have made is listed with the exact change they proposed.