PT0-002 · Question #146
A penetration tester is starting an assessment but only has publicly available information about the target company. The client is aware of this exercise and is preparing for the test. Which of the fo
The correct answer is C. Unknown environment testing. An assessment where the penetration tester only has publicly available information about the target company and no internal knowledge is classified as unknown environment testing. This approach simulates an external attacker with no privileged internal information, even if the cl
Question
A penetration tester is starting an assessment but only has publicly available information about the target company. The client is aware of this exercise and is preparing for the test. Which of the following describes the scope of the assessment?
Options
- APartially known environment testing
- BKnown environment testing
- CUnknown environment testing
- DPhysical environment testing
How the community answered
(19 responses)- C95% (18)
- D5% (1)
Why each option
An assessment where the penetration tester only has publicly available information about the target company and no internal knowledge is classified as unknown environment testing. This approach simulates an external attacker with no privileged internal information, even if the client is aware of the test.
Partially known environment testing (gray-box) implies some limited knowledge or access, more than just publicly available information.
Known environment testing (white-box) means the tester has full knowledge of the system architecture, source code, and configurations, which is not the case here.
Unknown environment testing, also known as a black-box test, is characterized by the penetration tester having little to no prior knowledge of the target's internal infrastructure, relying solely on publicly available information. Despite the client being aware, the tester's lack of internal access or specific system details makes it an 'unknown environment' from the tester's perspective, simulating an external attacker.
Physical environment testing refers to assessing physical security controls, which is not directly related to the information-gathering constraint described.
Concept tested: Penetration testing types - black-box
Topics
Community Discussion
No community discussion yet for this question.