nerdexam
CompTIA

SY0-501 · Question #394

A security analyst is attempting to break into a client's secure network. The analyst was not given prior information about the client, except for a block of public IP addresses that are currently…

The correct answer is A. a gray-box penetration test. After starting with public IP addresses and performing network enumeration, the analyst has gained partial information about the target, making a gray-box penetration test the appropriate next step to simulate an attacker with some internal knowledge.

Submitted by suresh_in· Mar 4, 2026Security operations

Question

A security analyst is attempting to break into a client's secure network. The analyst was not given prior information about the client, except for a block of public IP addresses that are currently in use. After network enumeration, the analyst's NEXT step is to perform:

Options

  • Aa gray-box penetration test.
  • Ba risk analysis.
  • Ca vulnerability assessment.
  • Dan external security audit.
  • Ea red team exercise.

How the community answered

(32 responses)
  • A
    72% (23)
  • B
    16% (5)
  • C
    3% (1)
  • D
    3% (1)
  • E
    6% (2)

Why each option

After starting with public IP addresses and performing network enumeration, the analyst has gained partial information about the target, making a gray-box penetration test the appropriate next step to simulate an attacker with some internal knowledge.

Aa gray-box penetration test.Correct

A gray-box penetration test involves the tester having some knowledge of the internal workings of the system, which is achieved by the analyst starting with public IPs and then gaining additional information through network enumeration. This partial knowledge allows for a more focused and efficient test than a pure black-box approach while not having full system access like a white-box test.

Ba risk analysis.

Risk analysis is a post-assessment activity that evaluates the impact and likelihood of identified vulnerabilities, not a direct testing step following network enumeration.

Ca vulnerability assessment.

While a vulnerability assessment identifies weaknesses, a gray-box penetration test is a more comprehensive next step that involves actively attempting to exploit those vulnerabilities based on the partial information gathered.

Dan external security audit.

An external security audit is a formal review of security controls, often compliance-driven, and is distinct from the active, hands-on penetration testing methodology described.

Ea red team exercise.

A red team exercise is a comprehensive, objective-based simulation of a real-world attack against an organization's entire defense, which is typically a larger-scale engagement than the immediate next step after initial enumeration.

Concept tested: Penetration testing methodologies (black-box, gray-box, white-box)

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing

Topics

#penetration testing#gray-box testing#network enumeration#reconnaissance

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice