mediumMultiple Choice
PT0-002 Practice Question: A multi-tenant SaaS application needs tenant…
A multi-tenant SaaS application needs tenant isolation testing. Which type of testing is most appropriate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Gray-box testing with a tenant account
Gray-box testing with a tenant account (D) is correct because the tester has legitimate authenticated access as one tenant, which is exactly what is needed to attempt cross-tenant access and verify isolation controls such as authorization checks, tenant ID scoping, and data segregation. This partial-knowledge approach lets testers probe APIs, object references, and session handling realistically without needing source code. White-box testing (A) requires source code access and is not necessary or typical for validating runtime tenant isolation. Vulnerability scanning of infrastructure (B) targets hosts and services, not application-level tenant boundaries, and black-box testing from the internet (C) lacks an authenticated tenant context needed to test cross-tenant access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
White-box testing with access to source code
Why it's wrong here
Source code access reveals filter logic but not the runtime behaviour of shared infrastructure, so it cannot confirm whether tenant identifiers are actually enforced at query time. It is tempting because code review exposes missing tenant predicates, and would suit static analysis of a single-tenant application's authorisation code.
- ✗
Vulnerability scanning of the underlying infrastructure
Why it's wrong here
Vulnerability scanning probes hosts and services for known CVEs and misconfigurations; it never attempts to cross tenant boundaries, so it cannot verify isolation. It is correct for finding patch gaps and exposed ports on the shared infrastructure itself.
- ✗
Black-box testing from the internet
Why it's wrong here
Internet-facing black-box testing only exercises tenant-facing endpoints, so it cannot reach the shared data layer, cache keys or query filters where cross-tenant leakage actually occurs. It is tempting because it mirrors an external attacker's view, and would suit perimeter or authentication testing of a deployed SaaS tenant.
- ✓
Gray-box testing with a tenant account
Why this is correct
Allows testing from an authenticated perspective.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.