CompTIA Security+ (SY0-701)Security Program Management and OversightEasy

A penetration tester is provided with the target's network diagrams, application source code, and valid user credentials prior to beginning the engagement. Which type of penetration test is being performed?

  1. ABlack-box test
  2. BBlind test
  3. CGray-box test
  4. DWhite-box test
Show answer & explanation

Correct answer: D. White-box test

A white-box test gives the tester full internal knowledge of the environment, including source code, architecture, and credentials, allowing for the most thorough assessment.

Why the other options are wrong

  • A. Black-box testing gives the tester no prior knowledge of the environment.
  • B. A blind test means the tester has no information, similar to black-box, but the organization is aware a test is occurring.
  • C. Gray-box testing provides only partial knowledge, such as limited credentials.

White-Box Penetration Test

A penetration test in which the tester has full knowledge of the target's internal systems, source code, and credentials before testing begins.

  • Also called clear-box or full-knowledge testing
  • Provides the most comprehensive test coverage
  • Contrasts with black-box (no knowledge) and gray-box (partial knowledge)

Memory trick: White box = wide-open view; black box = blind spot.

More Security Program Management and Oversight questions