nerdexam
CompTIA

CAS-003 · Question #334

A security analyst is attempting to break into a client's secure network. The analyst was not given prior information about the client, except for a block of public IP addresses that are currently…

The correct answer is A. a gray-box penetration test. Being given only a block of public IP addresses constitutes limited prior knowledge, defining this as a gray-box engagement; after completing enumeration, the analyst proceeds with the formal gray-box penetration test against identified targets.

Enterprise Security Operations

Question

A security analyst is attempting to break into a client's secure network. The analyst was not given prior information about the client, except for a block of public IP addresses that are currently in use. After network enumeration, the analyst's NEXT step is to perform:

Options

  • Aa gray-box penetration test
  • Ba risk analysis
  • Ca vulnerability assessment
  • Dan external security audit
  • Ea red team exercise

How the community answered

(59 responses)
  • A
    83% (49)
  • B
    2% (1)
  • C
    10% (6)
  • E
    5% (3)

Why each option

Being given only a block of public IP addresses constitutes limited prior knowledge, defining this as a gray-box engagement; after completing enumeration, the analyst proceeds with the formal gray-box penetration test against identified targets.

Aa gray-box penetration testCorrect

A gray-box penetration test is defined by the tester having partial, limited information about the target - in this case, only the assigned public IP block. Having completed network enumeration to map live hosts and services, the next logical step in the engagement is to proceed with exploitation and deeper testing under the gray-box methodology. This approach sits between black-box testing (no prior info) and white-box testing (full internal knowledge).

Ba risk analysis

A risk analysis is a management-level activity that evaluates threats and business impact rather than a hands-on technical follow-up step in an active penetration testing engagement.

Ca vulnerability assessment

A vulnerability assessment only identifies and catalogs vulnerabilities without actively exploiting them, making it a less comprehensive and less appropriate next step than a full penetration test.

Dan external security audit

An external security audit is a compliance-oriented documentation and review process, not an active adversarial technical activity that follows network enumeration.

Ea red team exercise

A red team exercise typically operates under black-box conditions with no prior information, which contradicts the scenario where the analyst was explicitly given a specific IP block to target.

Concept tested: Gray-box penetration testing methodology and scoping

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#penetration testing#network enumeration#security assessment methodology#gray-box testing

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice