nerdexam
CompTIA

SY0-301 · Question #655

Matt, the Chief Information Security Officer (CISO), tells the network administrator that a security company has been hired to perform a penetration test against his network. The security company…

The correct answer is B. The security company is provided with no information about the corporate network or physical locations. In a black box penetration test, the testing team begins with zero knowledge of the target environment, simulating an external attacker with no insider information.

Threats, vulnerabilities, and mitigations

Question

Matt, the Chief Information Security Officer (CISO), tells the network administrator that a security company has been hired to perform a penetration test against his network. The security company asks Matt which type of testing would be most beneficial for him. Which of the following BEST describes what the security company might do during a black box test?

Options

  • AThe security company is provided with all network ranges, security devices in place, and logical maps
  • BThe security company is provided with no information about the corporate network or physical locations.
  • CThe security company is provided with limited information on the network, including all network diagrams.
  • DThe security company is provided with limited information on the network, including some subnet ranges

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    93% (42)
  • D
    4% (2)

Why each option

In a black box penetration test, the testing team begins with zero knowledge of the target environment, simulating an external attacker with no insider information.

AThe security company is provided with all network ranges, security devices in place, and logical maps

Providing all network ranges, security devices, and logical maps describes white box (clear box) testing, where testers have full knowledge of the environment.

BThe security company is provided with no information about the corporate network or physical locations.Correct

Black box testing means the penetration testers are given no prior information about the target network, its architecture, IP ranges, security controls, or physical locations. This approach most accurately simulates a real-world external attacker who must perform all reconnaissance from scratch. The lack of provided information forces testers to discover everything themselves, providing the most realistic assessment of external attack exposure.

CThe security company is provided with limited information on the network, including all network diagrams.

Providing limited information including network diagrams describes gray box testing, a hybrid approach between black and white box.

DThe security company is provided with limited information on the network, including some subnet ranges

Providing limited information including some subnet ranges also describes gray box testing, not a true black box engagement.

Concept tested: Black box penetration testing methodology and scope

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#black box testing#penetration testing#security assessment

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice