nerdexam
CompTIA

SY0-701 · Question #927

During an assessment, an organization provides a penetration tester with a website URL and login credentials. However, the tester does not have access to the source code. Which of the following descri

The correct answer is A. Partially known. The tester has some internal knowledge (valid credentials and target URL) but lacks full visibility into the application internals/source code. That limited insight falls squarely into gray/partially known testing, which blends external attacker perspective with select insider in

Submitted by viktor_hu· Mar 6, 2026Security Operations

Question

During an assessment, an organization provides a penetration tester with a website URL and login credentials. However, the tester does not have access to the source code. Which of the following describes the type of test being performed?

Options

  • APartially known
  • BUnknown
  • CKnown
  • DObfuscated

How the community answered

(59 responses)
  • A
    78% (46)
  • B
    10% (6)
  • C
    3% (2)
  • D
    8% (5)

Explanation

The tester has some internal knowledge (valid credentials and target URL) but lacks full visibility into the application internals/source code. That limited insight falls squarely into gray/partially known testing, which blends external attacker perspective with select insider information to focus efforts efficiently.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice