easyMultiple Choice
PT0-002 Practice Question: A client requests a penetration test but only…
A client requests a penetration test but only provides network diagrams and application credentials. Which type of test is being scoped?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grey box
A grey box test provides the tester with limited information such as network diagrams and credentials, which matches the scenario. Black box tests provide no information, white box tests provide full information, and red team engagements are a type of test, not a box color.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Red team
Why it's wrong here
Red teaming is an objective-driven, full-scope adversarial simulation that tests people, processes, and technologies, not a classification of information sharing. It can be conducted using black, grey, or white box knowledge levels, so the term is orthogonal to the scenario. The client's question is about how much network information was provided, making Red team an incorrect answer here.
- ✗
Black box
Why it's wrong here
Black box testing assumes the tester starts with zero prior knowledge of the target, relying solely on public information and active reconnaissance. Since the client explicitly supplied network diagrams and credentials, the engagement already includes internal details that a black box tester would have to discover on their own. This provision contradicts the no-knowledge premise, so Black box cannot be the correct classification.
- ✓
Grey box
Why this is correct
Grey box testing occupies the middle ground between black and white box, giving the tester limited but realistic information such as network diagrams, IP ranges, and low-privileged credentials. This approach mirrors an insider or partially compromised external attacker and is the standard for many commercial penetration tests because it balances thoroughness with real-world conditions. The client's provision of network diagrams and credentials exactly matches this limited-information model, making Grey box the correct answer.
- ✗
White box
Why it's wrong here
White box testing, also known as full disclosure testing, grants the tester complete visibility into the environment, including application source code, architecture documentation, and administrative credentials. Merely providing network diagrams and standard user credentials falls far short of that complete knowledge level. Because the client only shared partial information rather than full transparency, the engagement cannot be classified as White box.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.