312-50V9 · Question #452
A penetration tester is hired to do a risk assessment of a company's DMZ. The rules of engagement states that the penetration test be done from an external IP address with no prior knowledge of the…
The correct answer is D. black box. A black box penetration test simulates an external attacker with no prior knowledge of the target's internal systems or architecture.
Question
A penetration tester is hired to do a risk assessment of a company's DMZ. The rules of engagement states that the penetration test be done from an external IP address with no prior knowledge of the internal IT systems. What kind of test is being performed?
Options
- Awhite box
- Bgrey box
- Cred box
- Dblack box
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- D90% (19)
Why each option
A black box penetration test simulates an external attacker with no prior knowledge of the target's internal systems or architecture.
White box testing provides the tester with full knowledge of the internal environment, including architecture, source code, and credentials, the opposite of this scenario.
Grey box testing provides partial knowledge such as some credentials or internal documentation, but this engagement explicitly states no prior knowledge.
Red box is not a standard penetration testing classification; the recognized categories are black, grey, and white box.
Black box testing means the tester starts with zero internal knowledge - no network diagrams, no credentials, no source code - mimicking a real external attacker. The rules of engagement here specify an external IP and no prior knowledge of internal IT systems, which exactly matches the black box definition.
Concept tested: Black box penetration testing methodology
Source: https://www.nist.gov/system/files/documents/2021/11/12/pentest-framework.pdf
Topics
Community Discussion
No community discussion yet for this question.