SY0-301 · Question #655
Matt, the Chief Information Security Officer (CISO), tells the network administrator that a security company has been hired to perform a penetration test against his network. The security company…
The correct answer is B. The security company is provided with no information about the corporate network or physical locations. In a black box penetration test, the testing team begins with zero knowledge of the target environment, simulating an external attacker with no insider information.
Question
Matt, the Chief Information Security Officer (CISO), tells the network administrator that a security company has been hired to perform a penetration test against his network. The security company asks Matt which type of testing would be most beneficial for him. Which of the following BEST describes what the security company might do during a black box test?
Options
- AThe security company is provided with all network ranges, security devices in place, and logical maps
- BThe security company is provided with no information about the corporate network or physical locations.
- CThe security company is provided with limited information on the network, including all network diagrams.
- DThe security company is provided with limited information on the network, including some subnet ranges
How the community answered
(45 responses)- A2% (1)
- B93% (42)
- D4% (2)
Why each option
In a black box penetration test, the testing team begins with zero knowledge of the target environment, simulating an external attacker with no insider information.
Providing all network ranges, security devices, and logical maps describes white box (clear box) testing, where testers have full knowledge of the environment.
Black box testing means the penetration testers are given no prior information about the target network, its architecture, IP ranges, security controls, or physical locations. This approach most accurately simulates a real-world external attacker who must perform all reconnaissance from scratch. The lack of provided information forces testers to discover everything themselves, providing the most realistic assessment of external attack exposure.
Providing limited information including network diagrams describes gray box testing, a hybrid approach between black and white box.
Providing limited information including some subnet ranges also describes gray box testing, not a true black box engagement.
Concept tested: Black box penetration testing methodology and scope
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.