Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A client requests a penetration test that…

A client requests a penetration test that simulates an external attacker with no prior knowledge of the internal network. The tester is not provided with any credentials, network diagrams, or source code. Which type of test does this describe?

⚠ Common exam trap

Many candidates confuse black-box testing with gray-box testing, mistakenly thinking that 'no credentials' automatically implies gray-box, but gray-box testing still provides some internal knowledge (e.g., network diagrams or low-privilege access), which is explicitly absent in this scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Black-box test

This is a black-box test because the tester simulates an external attacker with no prior knowledge of the internal network, no credentials, no network diagrams, and no source code. In black-box testing, the tester must discover all vulnerabilities from an outsider's perspective, relying solely on publicly available information and active reconnaissance techniques such as port scanning, service enumeration, and vulnerability scanning. This approach aligns with the client's requirement to mimic a real-world attacker who has zero insider knowledge.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • White-box test

    Why it's wrong here

    In a white-box (clear-box) test, the tester is given complete internal knowledge, including architecture diagrams, source code, and valid credentials, simulating an insider or someone with full system access. This does not match the request for an external simulation, which requires starting with zero knowledge and discovering vulnerabilities from the outside. The goal is to test the organization's external attack surface as an unprivileged outsider would see it.

  • Black-box test

    Why this is correct

    A black-box test accurately simulates an external attacker with no prior knowledge, forcing the tester to perform open-source intelligence (OSINT), port scanning, and service enumeration to identify entry points. Because the client requested an 'external' test, this aligns perfectly: the tester starts from the outside with only public information and any active exploitation must be done from external network boundaries. This approach mirrors a real-world attack and minimizes bias about where vulnerabilities exist.

  • Gray-box test

    Why it's wrong here

    A gray-box test provides the tester with partial insider knowledge, such as credentials for a low-privileged account or internal documentation, which saves time but does not replicate a truly external adversary. Since the request is for an external simulation, giving the tester any internal knowledge could mask flaws in perimeter security that a fully blind attacker would encounter. Thus it is wrong because it introduces an unrealistic advantage.

  • Covert test

    Why it's wrong here

    A covert test (red team) focuses on avoiding detection by the organization's security monitoring, not on the level of knowledge provided; tests can be black-box, white-box, or gray-box while still being covert. The client's request specifies 'external,' which is about the attack vector and information scope, not about whether the organization is aware of the test. Therefore, although a covert test may also involve external simulations, it does not inherently define the information given, so it is not the correct answer for this scenario.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.