mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A client wants a penetration test that simulates…
A client wants a penetration test that simulates an external threat actor with no prior access. The client provides a list of public IP ranges and domain names. Which type of test is this?
⚠ Common exam trap
Test-takers frequently confuse 'external' with 'black-box'—candidates may think a gray-box test is appropriate because the client provides some information, but the key is that no internal access or credentials are given, which strictly defines a black-box test.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External black-box test.
This is an external black-box test because the client provides only public IP ranges and domain names, simulating an external threat actor with no prior access. The tester has no internal knowledge or credentials, which defines a black-box approach, and the scope is limited to external-facing assets, making it external.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
External black-box test.
Why this is correct
An external black-box penetration test is the only option that matches both constraints: the tester operates from outside the network perimeter (external) and receives no architectural diagrams, credentials, or source code (black-box). This simulates a realistic external threat actor who must rely on OSINT, port scanning, and vulnerability discovery to gain an initial foothold. The client's requirement of 'no prior access' eliminates any internal vantage point or pre-supplied knowledge, making this the correct methodology.
- ✗
Internal white-box test.
Why it's wrong here
An internal white-box test is the antithesis of the scenario: it is performed from within the network and presupposes full knowledge of the environment, including network topology, source code, and sometimes administrative credentials. This approach is designed to identify insider threats or post-compromise impact, not to simulate an external attacker breaking in from the internet. Because the client explicitly wants an external simulation with no prior access, this option fails both the vantage point and the knowledge-level criteria.
- ✗
Gray-box test.
Why it's wrong here
A gray-box test involves partial knowledge, such as valid low-privilege credentials, API documentation, or internal architecture details, typically given to mimic an attacker who has already achieved a foothold or to speed up testing. The scenario's strict 'no prior access' condition means the tester starts with zero inside information, which is the hallmark of black-box testing. Supplying partial knowledge would artificially reduce the attack surface and would not faithfully emulate the external threat actor the client wants to simulate.
- ✗
Red team exercise.
Why it's wrong here
A red team exercise is a goal-oriented, adversarial simulation that may combine multiple techniques, but it often includes elements of stealth and evasion. The scenario is a straightforward penetration test with clear scope, not a full red team engagement.
Go deeper
Related to this question
About these practice questions
One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.