CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A penetration tester is hired to simulate a real-world external attacker and is given only the company's public domain name. The tester has no internal documentation, credentials, or architecture diagrams before the engagement begins. Which type of penetration test is being performed?
- AWhite-box test
- BBlack-box test
- CTabletop exercise
- DGray-box test
Show answer & explanationAnswer & explanation
Correct answer: B. Black-box test
A black-box penetration test simulates an external attacker with no prior internal knowledge of the target beyond publicly available information, requiring the tester to perform full reconnaissance.
Why the other options are wrong
- A. White-box testers receive full internal documentation and source code, the opposite of this scenario.
- C. A tabletop exercise is a discussion-based drill, not a technical penetration test.
- D. Gray-box testers receive partial information, such as credentials or a basic diagram.
Black-Box Penetration Test
A penetration test conducted with no prior internal knowledge of the target system, simulating an external attacker.
- Tester relies entirely on external reconnaissance
- Most realistic simulation of an outside attacker
- Contrasts with white-box (full knowledge) and gray-box (partial knowledge)
Memory trick: Black = blind, White = wide-open, Gray = a little of both.