CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A penetration tester is given valid user credentials and a basic network diagram before the engagement begins, but is not provided source code or full administrative documentation. Which type of penetration test is being performed?
- ARed team exercise
- BGray-box test
- CWhite-box test
- DBlack-box test
Show answer & explanationAnswer & explanation
Correct answer: B. Gray-box test
A gray-box test provides the tester with partial knowledge of the environment, such as user credentials and a network diagram, simulating the perspective of an insider with limited access rather than full source code and documentation.
Why the other options are wrong
- A. A red team exercise is an adversarial simulation exercise, not defined by the amount of knowledge shared.
- C. White-box testing provides full knowledge, including source code and complete documentation.
- D. Black-box testing provides no internal knowledge at all, simulating an external attacker.
Gray-Box Penetration Test
A penetration test in which the tester is given partial knowledge of the target environment, such as limited credentials or network diagrams, but not full internal documentation.
- Simulates an attacker with insider-level but limited access
- Balances the realism of black-box with the efficiency of white-box testing
- Contrast with black-box (no knowledge) and white-box (full knowledge)
Memory trick: Black=blind, White=full view, Gray=partial peek