Courseiva
easyMultiple Choice

PT0-002 Practice Question: A client requests a penetration test but only…

A client requests a penetration test but only provides network diagrams and application credentials. Which type of test is being scoped?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grey box

A grey box test provides the tester with limited information such as network diagrams and credentials, which matches the scenario. Black box tests provide no information, white box tests provide full information, and red team engagements are a type of test, not a box color.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Red team

    Why it's wrong here

    Red teaming is an objective-driven, full-scope adversarial simulation that tests people, processes, and technologies, not a classification of information sharing. It can be conducted using black, grey, or white box knowledge levels, so the term is orthogonal to the scenario. The client's question is about how much network information was provided, making Red team an incorrect answer here.

  • ✗

    Black box

    Why it's wrong here

    Black box testing assumes the tester starts with zero prior knowledge of the target, relying solely on public information and active reconnaissance. Since the client explicitly supplied network diagrams and credentials, the engagement already includes internal details that a black box tester would have to discover on their own. This provision contradicts the no-knowledge premise, so Black box cannot be the correct classification.

  • ✓

    Grey box

    Why this is correct

    Grey box testing occupies the middle ground between black and white box, giving the tester limited but realistic information such as network diagrams, IP ranges, and low-privileged credentials. This approach mirrors an insider or partially compromised external attacker and is the standard for many commercial penetration tests because it balances thoroughness with real-world conditions. The client's provision of network diagrams and credentials exactly matches this limited-information model, making Grey box the correct answer.

  • ✗

    White box

    Why it's wrong here

    White box testing, also known as full disclosure testing, grants the tester complete visibility into the environment, including application source code, architecture documentation, and administrative credentials. Merely providing network diagrams and standard user credentials falls far short of that complete knowledge level. Because the client only shared partial information rather than full transparency, the engagement cannot be classified as White box.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.