CompTIA Security+ (SY0-701)Security Program Management and OversightMedium

A penetration tester is given valid user credentials and a basic network diagram before the engagement begins, but is not provided source code or full administrative documentation. Which type of penetration test is being performed?

  1. ARed team exercise
  2. BGray-box test
  3. CWhite-box test
  4. DBlack-box test
Show answer & explanation

Correct answer: B. Gray-box test

A gray-box test provides the tester with partial knowledge of the environment, such as user credentials and a network diagram, simulating the perspective of an insider with limited access rather than full source code and documentation.

Why the other options are wrong

  • A. A red team exercise is an adversarial simulation exercise, not defined by the amount of knowledge shared.
  • C. White-box testing provides full knowledge, including source code and complete documentation.
  • D. Black-box testing provides no internal knowledge at all, simulating an external attacker.

Gray-Box Penetration Test

A penetration test in which the tester is given partial knowledge of the target environment, such as limited credentials or network diagrams, but not full internal documentation.

  • Simulates an attacker with insider-level but limited access
  • Balances the realism of black-box with the efficiency of white-box testing
  • Contrast with black-box (no knowledge) and white-box (full knowledge)

Memory trick: Black=blind, White=full view, Gray=partial peek

More Security Program Management and Oversight questions