CompTIA Security+ (SY0-701)Security Program Management and OversightEasy
A penetration tester is provided with the target's network diagrams, application source code, and valid user credentials prior to beginning the engagement. Which type of penetration test is being performed?
- ABlack-box test
- BBlind test
- CGray-box test
- DWhite-box test
Show answer & explanationAnswer & explanation
Correct answer: D. White-box test
A white-box test gives the tester full internal knowledge of the environment, including source code, architecture, and credentials, allowing for the most thorough assessment.
Why the other options are wrong
- A. Black-box testing gives the tester no prior knowledge of the environment.
- B. A blind test means the tester has no information, similar to black-box, but the organization is aware a test is occurring.
- C. Gray-box testing provides only partial knowledge, such as limited credentials.
White-Box Penetration Test
A penetration test in which the tester has full knowledge of the target's internal systems, source code, and credentials before testing begins.
- Also called clear-box or full-knowledge testing
- Provides the most comprehensive test coverage
- Contrasts with black-box (no knowledge) and gray-box (partial knowledge)
Memory trick: White box = wide-open view; black box = blind spot.