EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewMedium

A penetration tester is hired to evaluate the security posture of a financial institution. The scope of engagement explicitly states that the tester must not perform any denial-of-service attacks or modify production data. The tester is given a dedicated network segment with simulated production systems and accounts. What type of ethical hacking engagement is being conducted?

  1. AWhite Box Testing
  2. BRed Team Assessment
  3. CBlack Box Testing
  4. DGray Box Testing
Show answer & explanation

Correct answer: D. Gray Box Testing

Gray box testing involves the attacker having some knowledge of the internal network or system, but not full access or complete knowledge. In this scenario, the tester has 'simulated production systems and accounts,' indicating partial knowledge, which is characteristic of a gray box approach.

Why the other options are wrong

  • A. White box testing involves full knowledge of the internal systems, including source code and architecture, which is more than 'simulated accounts.'
  • B. Red team assessment is broader, simulating an advanced persistent threat, but the 'gray box' term specifically defines the knowledge level during the core penetration testing activity.
  • C. Black box testing involves no prior knowledge of the internal systems, which contradicts the scenario.

Gray Box Testing

A penetration testing method where the tester has partial knowledge of the internal system, such as user credentials, network diagrams, or access to non-critical internal applications.

  • Combines elements of black box and white box testing.
  • Simulates an attacker with some internal access or information.
  • Efficient for uncovering vulnerabilities from an insider perspective.
  • Requires some information sharing from the client.

Memory trick: Color your boxes by how much you know: Black, Gray, White.

More Information Security and Ethical Hacking Overview questions