SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium
A penetration tester is conducting a black-box assessment on a client's external web application. Which of the following best describes the information the penetration tester has access to at the start of the assessment?
- ADetailed vulnerability reports from previous internal assessments.
- BOnly publicly available information, with no prior knowledge of internal systems.
- CPartial source code and credentials for a non-privileged user.
- DFull source code, network diagrams, and system architecture.
Show answer & explanationAnswer & explanation
Correct answer: B. Only publicly available information, with no prior knowledge of internal systems.
A black-box penetration test simulates an attack by an external adversary with no prior knowledge of the target's internal systems or infrastructure, relying only on publicly available information.
Why the other options are wrong
- A. This would be provided in a white-box or gray-box assessment, not black-box.
- C. This describes a gray-box assessment.
- D. This describes a white-box (or crystal-box) assessment.
Black-box Testing
A type of security assessment where the tester has no prior knowledge of the internal workings, architecture, or source code of the system being tested.
- Simulates an external attacker.
- Relies on publicly available information and reconnaissance.
- Focuses on identifying vulnerabilities exploitable from an external perspective.
Memory trick: Box colors tell you how much you see inside.