SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium
A company is developing a new web application that will handle sensitive customer data. Before deployment, a security team conducts a thorough review to identify potential vulnerabilities by simulating attacks from the perspective of a malicious actor without prior knowledge of the internal system. Which type of security assessment is being performed?
- ABlack-box penetration test
- BGray-box penetration test
- CWhite-box penetration test
- DVulnerability scan
Show answer & explanationAnswer & explanation
Correct answer: A. Black-box penetration test
A black-box penetration test simulates an attack from an external hacker's perspective, with no prior knowledge of the internal system, focusing on what an attacker could discover and exploit from the outside. This matches the scenario description.
Why the other options are wrong
- B. Gray-box testing involves some limited knowledge, such as user credentials, but not full internal access.
- C. White-box testing involves full knowledge of the system's internal workings (source code, architecture).
- D. Vulnerability scanning automatically identifies known weaknesses but doesn't involve manual exploitation or simulating a full attack path.
Black-Box Penetration Test
A type of penetration test where the ethical hacker has no prior knowledge of the target system's internal structure, code, or architecture, simulating an external, unprivileged attacker.
- Simulates an attacker with no internal knowledge.
- Focuses on external vulnerabilities.
- Tests what an attacker can discover and exploit.
Memory trick: Boxes of knowledge: Black is blind, White is all, Gray is some.