Courseiva
Engagement Management →easyMultiple Choice

PT0-002 Engagement Management Practice Question

A penetration tester is hired to assess the security of a company's internal network. The client provides the tester with full network diagrams, credentials, and source code. Which type of penetration test is being performed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

White box

White box testing provides the tester with full knowledge and credentials, which matches the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grey box

    Why it's wrong here

    Grey box testing grants the tester partial knowledge, such as a valid low-privileged domain account or limited network diagrams, to emulate an authenticated internal threat. Because the engagement involves only piecemeal information rather than complete architectural and code-level details, it does not satisfy a scenario where the tester is granted full system knowledge. The correct answer must reflect total visibility, not a middle ground.

  • ✗

    Black box

    Why it's wrong here

    Black box testing provides no prior knowledge of the target, forcing the tester to perform reconnaissance and behave like an unprivileged external attacker. While this approach validates external perimeter controls, it cannot be selected when the engagement explicitly provides the tester with full credentials, source code, and infrastructure documentation. Lack of insider knowledge runs directly contrary to the premise that the tester has complete access.

  • ✗

    Red team

    Why it's wrong here

    Red teaming is a goal-based security exercise that emulates adversarial tactics, techniques, and procedures across multiple layers, not a knowledge-level classification like black, grey, or white box. A red team can operate with black, grey, or white knowledge depending on the rules of engagement, so selecting it as a testing type would mismatch the question's focus on the amount of information provided. The premise asks for a testing methodology defined by knowledge, not an operational exercise format.

  • ✓

    White box

    Why this is correct

    White box testing, also called clear box or open box testing, gives the tester full knowledge of the target environment, including source code, architecture diagrams, configuration files, and administrative credentials. This comprehensive visibility allows the pentester to perform detailed code review, identify programming flaws, and validate configuration hardening with maximum efficiency. When the engagement premise states the tester is provided complete system details, white box is the only correct classification.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.