SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium

A security team is preparing for a scheduled penetration test against their external-facing web applications. They want to ensure that the penetration testers have no prior knowledge of the internal network architecture, source code, or credentials, simulating a real-world attacker's perspective. Which type of penetration test engagement is being described?

  1. ADouble-blind test
  2. BGrey-box test
  3. CBlack-box test
  4. DWhite-box test
Show answer & explanation

Correct answer: C. Black-box test

A black-box penetration test simulates an attack from an external threat actor with no prior knowledge of the target system's internal details. This approach provides the most realistic assessment of an attacker's perspective.

Why the other options are wrong

  • A. A double-blind test means neither the testers nor the target organization (except for a few contacts) know the test is happening, which is a different aspect than knowledge level.
  • B. Grey-box tests involve partial knowledge, such as user-level credentials or network diagrams.
  • D. White-box tests involve full knowledge of the system, including source code and architecture.

Black-Box Penetration Test

A black-box penetration test is an authorized cyberattack simulation where the testers have no prior knowledge of the target system's internal structure or code, mimicking an external attacker.

  • Simulates an unprivileged attacker.
  • Focuses on external vulnerabilities.
  • Provides a realistic view of external attack surfaces.

Memory trick: Box types: White sees all, Grey sees some, Black sees none.

More Security Operations and Administration questions