Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementEasy

A security auditor is conducting a 'black-box' penetration test on a client's external web application. Which of the following statements accurately describes the primary characteristic of this type of assessment?

  1. AThe auditor uses automated tools exclusively to identify vulnerabilities without manual intervention.
  2. BThe auditor is provided with limited, non-privileged access to the application's internal network.
  3. CThe auditor has full access to the application's source code and system architecture diagrams.
  4. DThe auditor has no prior knowledge of the internal workings of the application or infrastructure.
Show answer & explanation

Correct answer: D. The auditor has no prior knowledge of the internal workings of the application or infrastructure.

A black-box penetration test simulates an external attacker with no prior knowledge of the target system's internal structure, code, or configurations. This tests the system's defenses from an unprivileged perspective.

Why the other options are wrong

  • A. Automated tools can be used, but black-box testing isn't exclusively automated and often involves manual techniques.
  • B. Limited, non-privileged access describes a grey-box test.
  • C. Full access to source code and diagrams describes a white-box test.

Black-Box Penetration Testing

Black-box penetration testing is a type of security assessment where the tester has no prior knowledge of the target system's internal structure, source code, or infrastructure.

  • Simulates an external attacker.
  • Focuses on publicly exposed interfaces and common attack vectors.
  • Requires more time for reconnaissance and discovery.

Memory trick: BOXES: Black (unknown), Gray (some), White (all).

More Vulnerability Management questions