Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementMedium

A security analyst is performing a black-box penetration test against a client's external web application. During the reconnaissance phase, the analyst discovers several subdomains and public-facing IP addresses, but no direct access to source code or internal network diagrams. Which of the following best describes the perspective and information available to the analyst at this stage?

  1. AThey have an insider's view, similar to a malicious employee.
  2. BThey have partial knowledge, similar to a privileged user.
  3. CThey are operating with full system knowledge and access.
  4. DThey are simulating an external, unauthenticated attacker.
Show answer & explanation

Correct answer: D. They are simulating an external, unauthenticated attacker.

A black-box penetration test explicitly simulates an external, unauthenticated attacker with no prior knowledge of the internal system. Discovering public-facing information like subdomains and IPs aligns with the reconnaissance phase of such a test.

Why the other options are wrong

  • A. This describes a 'white-box' or 'gray-box' test with insider access.
  • B. Partial knowledge implies a 'gray-box' test, which is not black-box.
  • C. Full system knowledge is characteristic of a 'white-box' test, where the tester has access to source code, architecture, etc.

Black-Box Penetration Test

A type of penetration test where the tester has no prior knowledge of the target system's internal structure or source code, simulating an external attacker.

  • Mimics a real-world external attacker.
  • Focuses on identifying vulnerabilities visible from the outside.
  • Requires extensive reconnaissance by the tester.

Memory trick: Black-box is 'Blind' testing, like an attacker from outside.

More Vulnerability Management questions