CAS-003 · Question #334
A security analyst is attempting to break into a client's secure network. The analyst was not given prior information about the client, except for a block of public IP addresses that are currently…
The correct answer is A. a gray-box penetration test. Being given only a block of public IP addresses constitutes limited prior knowledge, defining this as a gray-box engagement; after completing enumeration, the analyst proceeds with the formal gray-box penetration test against identified targets.
Question
A security analyst is attempting to break into a client's secure network. The analyst was not given prior information about the client, except for a block of public IP addresses that are currently in use. After network enumeration, the analyst's NEXT step is to perform:
Options
- Aa gray-box penetration test
- Ba risk analysis
- Ca vulnerability assessment
- Dan external security audit
- Ea red team exercise
How the community answered
(59 responses)- A83% (49)
- B2% (1)
- C10% (6)
- E5% (3)
Why each option
Being given only a block of public IP addresses constitutes limited prior knowledge, defining this as a gray-box engagement; after completing enumeration, the analyst proceeds with the formal gray-box penetration test against identified targets.
A gray-box penetration test is defined by the tester having partial, limited information about the target - in this case, only the assigned public IP block. Having completed network enumeration to map live hosts and services, the next logical step in the engagement is to proceed with exploitation and deeper testing under the gray-box methodology. This approach sits between black-box testing (no prior info) and white-box testing (full internal knowledge).
A risk analysis is a management-level activity that evaluates threats and business impact rather than a hands-on technical follow-up step in an active penetration testing engagement.
A vulnerability assessment only identifies and catalogs vulnerabilities without actively exploiting them, making it a less comprehensive and less appropriate next step than a full penetration test.
An external security audit is a compliance-oriented documentation and review process, not an active adversarial technical activity that follows network enumeration.
A red team exercise typically operates under black-box conditions with no prior information, which contradicts the scenario where the analyst was explicitly given a specific IP block to target.
Concept tested: Gray-box penetration testing methodology and scoping
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.