Best Practices and Summary
So, we’ve learned about the most popular cloud platforms—AWS, Azure, and GCP. We’ve also tried out a bunch of vulnerability scanning and pentesting exercises in our own test AWS, Azure, and GCP deployments.
Now, let’s review what we’ve learned. We’ll also give you useful information about professional certifications, pentesting contracts, and pentest reports. In this chapter, we’ll cover a content review with questions and answers based on the material that appeared earlier in this book, what you should have in your cloud pentesting toolkit, and useful cloud and pentesting certifications that you can pursue.
We will also discuss what should be included in a pentesting contract and how to write an effective pentest report.
We’ll cover the following main topics:
- Content review
- Your cloud pentesting toolkit
- Cloud and pentester certifications
- Pentesting contracts
- Pentesting...