Courseiva
Engagement Management →easyMultiple Choice

PT0-002 Engagement Management Practice Question

A penetration tester is hired to perform an assessment where the tester is provided with network diagrams, source code, and administrative credentials. Which type of penetration test is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

White box

In a white box test, the tester has full knowledge of the environment, including credentials and documentation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grey box

    Why it's wrong here

    Grey box testing is incorrect here because it involves only partial knowledge of the system, such as a set of low-privileged credentials or a subset of network diagrams. In a grey box engagement, the tester must still perform enumeration and privilege escalation to uncover vulnerabilities, whereas the prompt explicitly states that full knowledge and credentials are provided. This level is typically used to simulate an authenticated insider or a user with specific, limited access, not the complete access described in the assessment.

  • ✗

    Black box

    Why it's wrong here

    Black box testing is incorrect because it simulates an external attacker with zero prior knowledge of the target environment. The tester must rely solely on OSINT, port scanning, service enumeration, and manual exploitation to discover entry points, which is the opposite of being provided full knowledge and credentials. Since the prompt specifies that the assessor receives complete architectural information and valid credentials, the scenario cannot be classified as black box, as that would obscure the very information that has been explicitly granted.

  • ✓

    White box

    Why this is correct

    White box testing is the correct classification because the scenario describes a penetration tester who is given full knowledge of the system, including source code, network architecture, and authorized credentials. This testing level, also known as crystal box or clear box, allows comprehensive vulnerability identification, including deep logic flaws and configuration issues, and is often used for compliance-driven reviews or post-breach security assessments. The provision of full knowledge enables the tester to focus on exploitation and reporting without spending time on reconnaissance, directly matching the prompt's conditions.

  • ✗

    Red team

    Why it's wrong here

    Red team is incorrect because it refers to an engagement type that simulates real-world adversarial attacks to test detection and response capabilities, not a classification of the tester's knowledge level. A red team operation can be performed as black, grey, or white box depending on the client's objectives, such as testing how well the blue team detects an attack. The prompt asks for a testing knowledge level, and while a red team may be given full knowledge, the term itself does not inherently define the level of access or information provided, making it an unsuitable answer.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.