Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A security auditor is performing a vulnerability assessment for a client. The client provides the auditor with network diagrams, system configurations, and authentication credentials for all target systems. What type of assessment methodology is the auditor employing?

  1. AGray-box assessment
  2. BWhite-box assessment
  3. CExternal penetration test
  4. DBlack-box assessment
Show answer & explanation

Correct answer: B. White-box assessment

A white-box assessment (also known as crystal-box or clear-box) involves providing the assessor with full knowledge of the target system's internal workings, including architecture, source code, and credentials. This allows for a very thorough and deep analysis.

Why the other options are wrong

  • A. A gray-box assessment provides partial knowledge or limited credentials, falling between black-box and white-box.
  • C. An external penetration test refers to the origin of the test (outside the network) and can be black, white, or gray box depending on information provided.
  • D. A black-box assessment is performed with no prior knowledge of the internal system, simulating an external attacker.

White-box Assessment

A type of security assessment where the assessor has complete knowledge of the target system's internal structure, design, and often credentials.

  • Provides maximum visibility into system internals.
  • Allows for thorough analysis of code, configurations, and architecture.
  • Often used for comprehensive vulnerability assessments and source code reviews.

Memory trick: Black knows nothing, Gray knows some, White knows all.

More Vulnerability Management questions