Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium
A security auditor is performing a vulnerability assessment for a client. The client provides the auditor with network diagrams, system configurations, and authentication credentials for all target systems. What type of assessment methodology is the auditor employing?
- AGray-box assessment
- BWhite-box assessment
- CExternal penetration test
- DBlack-box assessment
Show answer & explanationAnswer & explanation
Correct answer: B. White-box assessment
A white-box assessment (also known as crystal-box or clear-box) involves providing the assessor with full knowledge of the target system's internal workings, including architecture, source code, and credentials. This allows for a very thorough and deep analysis.
Why the other options are wrong
- A. A gray-box assessment provides partial knowledge or limited credentials, falling between black-box and white-box.
- C. An external penetration test refers to the origin of the test (outside the network) and can be black, white, or gray box depending on information provided.
- D. A black-box assessment is performed with no prior knowledge of the internal system, simulating an external attacker.
White-box Assessment
A type of security assessment where the assessor has complete knowledge of the target system's internal structure, design, and often credentials.
- Provides maximum visibility into system internals.
- Allows for thorough analysis of code, configurations, and architecture.
- Often used for comprehensive vulnerability assessments and source code reviews.
Memory trick: Black knows nothing, Gray knows some, White knows all.